Mobile numbers, details of lakhs left exposed on Chhatron Ki Goonj website of Rahul Gandhi
· OpIndia
In June this year, Congress leader Rahul Gandhi launched a campaign named “Chhatron Ki Goonj” (echoes of students) purportedly to raise issues of students, such as paper leaks, higher cost of education, lack of opportunities, etc. Congress has since organized many events by this name where Rahul Gandhi interacts with students, listens to their grievances, and promises to fix them all, if Congress wins elections.
In order to attend such events, or to become part of this “student’s movement” as the Congress party wants to call it, young students from schools and colleges are supposed to register on a website. The website hosting the registration form for Chhatron Ki Goonj is incidentally Rahul Gandhi’s personal website hosted at the URL rahulgandhi.in
Visit bettingx.bond for more information.
Back in June, Rahul Gandhi himself had exhorted students to register on the website:
If you've suffered because of paper leaks, exam issues, or high fees
— Rahul Gandhi (@RahulGandhi) June 18, 2026
If this education system has shattered your dreams
If your family has invested a lifetime of savings in your education
Then “Chhatron Ki Goonj” is your voice.
This isn't just a campaign – it's a platform to…
He had even posted a video appeal after the first Chhatron Ki Goonj event in Kota, Rajasthan, asking students to share more ideas. He showed a QR code in the video, which took the students to the same Chhatron Ki Goonj registration form hosted on his personal website.
कोटा, आप कमाल थे।
— Rahul Gandhi (@RahulGandhi) June 18, 2026
यकीन मानिए, कल हमने मिलकर इतिहास की शुरुआत की।
हज़ारों छात्र मैदान में थे, लाखों लोगों ने ऑनलाइन देखा – और देश को पहली बार खुलकर पता चला कि शिक्षा के नाम पर कितनी बड़ी वसूली चल रही है।
लेकिन यह तो सिर्फ़ शुरुआत है। कोटा में जो लौ जली है, उसे अब पूरे देश में… pic.twitter.com/UWdXQ9vXjD
It is fair to say that Rahul Gandhi personally drove thousands of students to his personal website where they were supposed to provide their names, mobile numbers, gender, and other personal data in order to register for the Chhatron Ki Goonj events, or merely to show support for Rahul Gandhi’s ideas and leadership.
Now it seems that whoever trusted Rahul Gandhi’s words were exposed to potential data leak, where scammers and hackers could misuse their personal data to target them. This could include sending suspicious links to hack social media accounts, or to defraud them into paying some money, or to do worse things like cyberbullying or extracting ransom via stunts like digital arrests.
Ironically whenever any student, including minors, landed on the website promoted by Rahul Gandhi to register themselves, they were assured with a message saying their number was not up for sale i.e. the information provided by them will be safe and secure from scammers or telemarketers:
Screenshot of Chhatron Ki Goonj section on Rahul Gandhi’s personal websiteHowever, truth can be far from that as revealed by a developer, researcher and security expert named Shashi, who put out a detailed blog post on various vulnerabilities on websites run by the Congress party.
Websites of Rahul Gandhi, Mahila Congress involved in leak
Shashi says that he could observe at least 1,56,439 records that are potentially exposed to misuse on Rahul Gandhi’s personal website at the time of writing his blog post, and of almost 6 lakh others on Mahila Congress website earlier.
These records could have been obtained by anyone who had understanding and knowledge of how cybersecurity works. Essentially one did not need to “hack” into Rahul Gandhi’s website to obtain these records. No brute-force entry or breaking of passwords was needed, one could get these numbers and data just by observing the publicly available codes, scripts, API calls, and some guesswork.
Rahul Gandhi's own website is collecting Gen Z students' personal data through its ongoing "Chhatron Ki Goonj" campaign.
— shashi (@devzoy) September 20, 2026
1.5 lakh+ records of those who registered on the site were exposed and could be retrieved at scale through a check-registration endpoint. pic.twitter.com/OLIwEnN7sg
Such security vulnerabilities were not limited to the Chhatron Ki Goonj Rahul Gandhi’s website alone, the expert says that he found serious vulnerabilities on other Congress-affiliated platforms as well, most notably the Mahila Congress website i.e. Congress was not compromising personal data of just students, but also of women who chose to trust them with their data.
It should be noted that there are thousands of active groups and individuals, known as underground data brokers or dump sellers, who keep trawling the internet to look for websites that have such vulnerabilities in their database. They take a dump (copy) of all such data and then put on dark web for sale, which is then used by other cybercriminals to target the affected individuals whose data was leaked.
A website or platform with weak data protection is expected to alert their users for any possible breach, so that affected users can take steps to secure themselves, such as changing their passwords on other websites if they were having a common password, or to delete other public data.
However, Congress did not do any of these despite being suggested to do so by security expert Shashi, who has given a detailed account of how he found out these security vulnerabilities on Congress websites. In his blog post, the security expert has given a detailed timeline for sake of transparency on how his first reaction was to alert the Congress party about the potential breach.
Congress party did not take complaints of data leak seriously
These vulnerabilities, rather poor cybersecurity protocols employed by the Congress party, were spotted more than a month ago by the security expert who wrote to the party functionaries alerting them about the same. He pointed out to them that many of these vulnerabilities were critical in nature and they should fix it as soon as possible.
However, no one officially associated with the Congress party bothered to acknowledge the problem to him or in public, though the vendors handling the websites informed the security expert that party authorities had been apprised of the situation.
After waiting for more than a week, the security expert then wrote to CERT-In i.e. Indian Computer Emergency Response Team, which is the national nodal agency for responding to computer security incidents as and when they occur. CERT-In is a functional organization of Ministry of Electronics and Information Technology of the Government of India (MeitY). CERT-In team immediately responded and asked for further information. After undertaking basic due diligence in such cases, CERT-In then proceeds to inform the affected party.
Possibly after being nudged by CERT-In, the Congress party finally acted and a member of their tech team reached out to the security expert on X (formerly Twitter). Most pages of the Congress party collecting information and donation were immediately disabled after this, which shows that the party accepted that there indeed was a major issue with the way they were handling personal data of users.
After a few days, the Congress party told the security expert that they have fixed all issues, though the security expert says that CERT-In has not yet provided any communication about formal closure. OpIndia has reached out to MeitY to inquire if a communication or report about closure of an issue is indeed part of their standard operating procedure or CERT-In only alerts the affected parties.
Poor cybersecurity protocols employed by the Congress party
How seriously Congress took the private data of their members and supporters, especially of women and students, can be known by the fact that following vulnerabilities were spotted by the security expert:
- You didn’t necessarily need possession of someone’s phone to obtain the OTP to login to Mahila Congress website. Instead of looking at any SMS, the person needed to look into API response visible through browser developer tools. A ‘master OTP’ was also present in the code, visible to people familiar with how web applications work.
- Without logging in, you could get details like address, age, gender etc. of a user, presumably Mahila Congress member, if you entered a mobile number.
- Again, without logging in, especially on Mahila Congress website, a user could map which Mahila Congress volunteer was ‘recruited’ by which another volunteer. A scammer could then impersonate the ‘recruiter’ to send messages to scam the unsuspecting Mahila Congress member.
- Profile pictures were easily accessible and were not stored behind a login protected layer.
- On Rahul Gandhi’s website, you didn’t even need an account, password, cookie, token or API key to query registration records. This is where Rahul Gandhi had been asking lakhs of students to submit their personal data.
Despite such serious flaw in data privacy and cybersecurity employed by them, Congress party and Rahul Gandhi have failed to publicly acknowledge their mistake that can potentially be exploited by scammers and cybercriminals. A public acknowledgement and apology could have alerted the women and students to take steps to secure their private data – any public or private organization has this social responsibility towards their users.
This is also not for the first time that the Congress party has been found irresponsible in handling personal data of their supporters and members. In the year 2021, Congress party had announced making an online army of over 5 lakhs volunteers on social media, and the website launched for that purpose too had suffered leak of personal data and breach of security.
It is ironic that through his Chhatron Ki Goonj campaign, Rahul Gandhi is attacking Prime Minister Narendra Modi for playing with the future of students, but his own website is endangering the present of the same students, especially those who chose to trust Rahul Gandhi with their personal data.