For Rs 2, Buy Name, Address, Other Details Of Any Vehicle Owner
A startling revelation has been reported from the Internet Freedom Foundation (IFF) regarding the massive security flaws surrounding India’s transport registers, where the personal details of lakhs of vehicle owners are reportedly being sold online for as little as two rupees.
Despite official claims that citizen data is securely protected behind masked portals, according to IFF, an investigation triggered by a concerned citizen has revealed that private smartphone applications, websites, and Telegram channels are routinely harvesting and selling sensitive information from government databases—including VAHAN, SARATHI, e-Challan, and PUC records.
In one alarming test of a popular Android application boasting over 10 million downloads, researchers managed to purchase fifteen search credits for just Rs 29 — working out to roughly Rs 1.93 per lookup. By simply entering a vehicle registration number, without requiring any login credentials or One-Time Password (OTP) verification, the app instantly returned the owner’s full name, father’s name, present and permanent addresses, financier details, insurance policy numbers, chassis and engine numbers, and PUC certificate details.
“The first Play Store app named in the complaint, listed as “Vehicle Information App” (package rto.owner.address.parivahan.car.malik.address.finder), showed over 10 million downloads and a last update of 31 July 2026 when we examined it. It sells 15 search credits for ₹29, which works out to roughly ₹1.93 a lookup. We ran a single search, on a vehicle belonging to a member of IFF’s staff who consented to it, and searched no other vehicle,” reports the IFF.

Vehicle Information App
While the government’s Transport department’s Parivahan portal deliberately masks such sensitive data to safeguard public privacy, this third-party app exposed the unmasked records in full. The app’s disclaimer claimed that all displayed data was publicly available on government platforms, an assertion that is demonstrably false given the stringent masking applied on official sites.
The privacy crisis extends far beyond commercial mobile applications. A separate investigation by cybersecurity firm Cyderes uncovered a Telegram-based brokerage service selling full vehicle registration details — including linked mobile numbers — for just Rs 5 per search. The investigation highlighted that this leak was not caused by a direct hack of government servers, but rather through the misuse of legitimate API credentials issued to licensed identity-verification and data enrichment companies. These credentials, granted under government data-sharing frameworks, were effectively being routed through unauthorised channels without adequate downstream checks.
The roots of this widespread exposure trace back to March 2019, when the Ministry of Road Transport and Highways (MoRTH) introduced a controversial Bulk Data Sharing Policy. Commercial organisations were permitted to buy annual access to national transport databases for Rs 3 crore. Although the policy was officially scrapped in June 2020 after authorities acknowledged the high risk of commercial misuse, vast tranches of historical data were never recalled or deleted. Over the years, these records have continued to circulate freely across global servers and private firms.
Under the new National Transport Repository (NTR) policy introduced in August 2025, over 39 crore vehicle records and 22 crore driving licences were consolidated into a single unified repository. While the policy mandates strict consent protocols via Aadhaar-authenticated OTPs for private access, technical experts argue that the current system trusts the API credential rather than verifying the actual end user. Consequently, third-party services are easily exploiting these long-lived API tokens to scrape personal data at scale.
The potential dangers of such accessible personal data are severe, according to experts. Combining a vehicle registration plate — which is publicly displayed on every automobile by law — with a home address, mobile number, and family details creates an immediate safety risk. Stalkers, fraudsters, and malicious and criminal actors can easily track down individuals, witnesses, or journalists.
— Internet Freedom Foundation (@internetfreedom)
In response to these findings, the IFF has formally written to senior officials at MoRTH, the National Informatics Centre (NIC), and CERT-In, requesting an immediate cyber security incident investigation. The advocacy group has called for a comprehensive forensic audit, the immediate preservation of API and server logs, and a complete technical overhaul to replace contractual undertakings with strict digital access controls. RTI applications have also been filed by the IFF to determine which private entities hold active credentials and whether any action has been taken against rogue data brokers.