Home News National Rahul Gandhi’s ‘Chhatron Ki Goonj’ Website Reportedly Exposed 1.5 Lakh+ Students’ Names,...

Rahul Gandhi’s ‘Chhatron Ki Goonj’ Website Reportedly Exposed 1.5 Lakh+ Students’ Names, Mobile Numbers And Personal Data

Rahul Gandhi’s ‘Chhatron Ki Goonj’ Website Reportedly Exposed 1.5 Lakh+ Students’ Names, Mobile Numbers And Personal Data

Congress leader Rahul Gandhi’s “Chhatron Ki Goonj” campaign, launched in June 2026 to highlight issues faced by students, has come under scrutiny over alleged cybersecurity vulnerabilities that could have exposed the personal information of people who registered through the campaign website, as reported in OpIndia.

The campaign was launched by Rahul Gandhi as a platform to raise issues including paper leaks, rising education costs, exam-related problems and lack of employment opportunities. Congress has since organised several “Chhatron Ki Goonj” events across the country, where Gandhi interacts with students, hears their grievances and presents the campaign as a movement for education reform.

Students seeking to attend these events or participate in the campaign are asked to register online. The registration form is hosted on Rahul Gandhi’s personal website, rahulgandhi.in. The website currently describes the campaign as a platform for students and asks visitors to provide details including their full name, mobile number, gender, state and their experiences with the education system.

The website also carries the assurance, “Your number is not for sale.”

Image Source: OpIndia
Rahul Gandhi Personally Promoted Registration

Rahul Gandhi himself promoted the campaign and encouraged students to participate. Following the first “Chhatron Ki Goonj” event in Kota, Rajasthan, he posted a video appeal on June 18 asking students to share their ideas. The video included a QR code that directed users to the same registration form on his personal website.

As a result, students, including potentially minors, were directed to a website where they were asked to submit personal information to register for events or participate in the campaign.

However, according to developer, researcher and security expert Shashi, the registration system contained vulnerabilities that potentially exposed large numbers of these records.

In a detailed account published after examining Congress-affiliated websites, Shashi said he was able to observe at least 1,56,439 records on Rahul Gandhi’s website that were potentially accessible for misuse. He had earlier identified similar vulnerabilities involving almost six lakh records on the Mahila Congress website.

Data Could Allegedly Be Accessed Without Hacking

According to Shashi, accessing the records did not require conventional hacking, brute-force attacks or breaking passwords. He said the information could be retrieved by someone familiar with web applications by examining publicly available code, scripts, API calls and making certain inferences.

Shashi specifically alleged that registration records on Rahul Gandhi’s website could be queried without an account, password, cookie, authentication token or API key. He said more than 1.5 lakh records registered through the “Chhatron Ki Goonj” campaign were exposed through a registration-check endpoint and could be retrieved at scale.

The potential exposure is significant because the campaign was specifically directed at students and collected information such as names and mobile numbers. The information could potentially be used by scammers or other cybercriminals for targeted phishing, fraud, social-media account compromise, impersonation or other forms of cybercrime.

Mahila Congress Website Also Flagged

The alleged vulnerabilities were not restricted to Rahul Gandhi’s website.

Shashi said he also found serious security flaws on the Mahila Congress website, potentially exposing information belonging to women who had registered or volunteered through the platform. According to his findings, these included vulnerabilities that could allow access to user information without proper authentication.

Among the issues he identified was an alleged method through which an individual could obtain an OTP response through browser developer tools rather than accessing the user’s phone. He also claimed that a “master OTP” was present in the website’s code and could be visible to people familiar with web applications.

Another alleged vulnerability allowed details such as a user’s address, age and gender to be retrieved by entering a mobile number, without logging in.

The researcher further said that the Mahila Congress platform allowed users to map which volunteer had recruited another volunteer. According to him, this could potentially allow a scammer to impersonate a recruiter and send fraudulent messages to unsuspecting members.

He also said profile pictures were accessible without being placed behind a login-protected layer.

Security Expert Says Congress Was Alerted But Did Not Take It Seriously

According to Shashi’s account, the vulnerabilities were identified more than a month before his findings were made public. He said he initially contacted Congress functionaries and warned them that several of the vulnerabilities were critical and required urgent attention.

He claimed that he did not receive an official acknowledgement from Congress, although the vendors handling the websites reportedly informed him that the party authorities had been made aware of the issue.

After waiting for more than a week, Shashi said he approached the Indian Computer Emergency Response Team (CERT-In), the national agency responsible for responding to cybersecurity incidents. CERT-In reportedly responded and sought additional information before proceeding with its own due diligence.

According to the account, Congress subsequently contacted Shashi through a member of its technology team on X. Several Congress pages that collected information and donations were then disabled.

The researcher said Congress later informed him that the identified issues had been fixed. However, he said he had not received communication from CERT-In confirming a formal closure of the matter.

Why Exposed Data Could Be A Concern

The security concern goes beyond simply making a database visible. Large databases containing names, mobile numbers, demographic information and other personal details can potentially be valuable to data brokers and cybercriminals.

Underground data brokers and “dump sellers” routinely search for databases that have been improperly exposed online. Such data can subsequently be copied and circulated or sold, potentially allowing criminals to target individuals with phishing messages, fraudulent calls, malicious links or impersonation attempts.

In cases involving compromised personal information, affected users can potentially take precautions such as changing reused passwords, securing social-media accounts and being cautious about unsolicited messages or calls.

The security expert’s account said Congress was advised about the need to alert potentially affected users, but alleged that the party did not publicly disclose the issue or notify users at the time.

Congress Had Faced Similar Data Security Questions Earlier

The latest allegations are also not the first time a Congress-linked online platform has faced questions over data security.

In 2021, Congress announced plans to build an online network of more than five lakh volunteers as part of its social-media outreach. The website created for the initiative was subsequently reported to have suffered security vulnerabilities and exposure of personal information.

The latest episode has drawn particular attention because of the nature of the “Chhatron Ki Goonj” campaign. Rahul Gandhi has used the initiative to highlight problems affecting students and has urged young people to participate and share their experiences.

His campaign website continues to present itself as a platform for students to raise their voices on issues such as paper leaks, fees, infrastructure and employment, while assuring visitors that their phone numbers are not for sale.

The cybersecurity researcher’s findings, however, allege that the very registration system through which students were encouraged to participate had security weaknesses that could have allowed large-scale access to registration records.

Congress has reportedly told the researcher that the vulnerabilities have since been fixed. The status of any formal CERT-In closure, however, remained unclear in the account published by the researcher.

Subscribe to our channels on WhatsAppTelegram, Instagram and YouTube to get the best stories of the day delivered to you personally.