Last Updated:
BJP targets Rahul Gandhi over alleged exposure of students’ personal details on his ‘Chhatron Ki Goonj’ campaign website. A report claims mobile numbers were exposed.

BJP Slams Rahul Gandhi After Mobile Numbers Exposed On Chhatron Ki Goonj Website.
(Image/PTI)
The Bharatiya Janata Party (BJP) has targeted Congress leader Rahul Gandhi over alleged exposure of students’ personal details on the website used for his ‘Chhatron Ki Goonj’ campaign.
BJP spokesperson Pradeep Bhandari said Rahul Gandhi was “playing with the present and future of students” by asking them to register on the platform using their phone numbers and other details. “These details are easily available for scammers to target students. Will Rahul Gandhi take responsibility if a young boy or girl falls prey to cybercriminals?” Bhandari said.
His remarks came after a report claimed that mobile numbers and other details of lakhs of people were potentially exposed on the Chhatron Ki Goonj website.
Rahul Gandhi is playing with present and future of students. He is asking them to register on Chhatron Ki Goonj website by submitting their phone numbers and other details.These details are easily available for scammers to target students.
Will Rahul Gandhi take…
— Pradeep Bhandari(प्रदीप भंडारी)🇮🇳 (@pradip103) September 21, 2026
Students asked to share personal details
Rahul Gandhi launched the Chhatron Ki Goonj campaign in June to raise issues concerning students, including paper leaks, the rising cost of education and lack of opportunities.
Congress has since organised several events under the campaign, where Gandhi interacts with students, hears their grievances and promises to address them if Congress wins elections. Students wishing to attend the events or become part of the movement have been asked to register through a website. The registration form is hosted on Gandhi’s personal website, rahulgandhi.in.
Gandhi had also urged students to register on the website and, after the first Chhatron Ki Goonj event in Kota, Rajasthan, posted a video asking students to share more ideas. The video displayed a QR code that directed users to the same registration form.
The form required students to provide their names, mobile numbers, gender and other personal information.
Researcher flags alleged vulnerabilities
According to an OpIndia report, developer, researcher and security expert Shashi published a detailed blog about vulnerabilities on websites run by the Congress party. Shashi said he could observe at least 1,56,439 records that were potentially exposed to misuse on Gandhi’s website when he wrote the blog. The report also said almost six lakh records had earlier been potentially exposed on the Mahila Congress website.
The researcher said accessing the records did not necessarily require hacking, brute-force attacks or breaking passwords. According to his account, the information could be accessed by observing publicly available codes, scripts and API calls, along with some guesswork.
The report said the alleged vulnerabilities extended beyond the Chhatron Ki Goonj website to other Congress-affiliated platforms.
Security expert alerted Congress, CERT-In
The security expert said he had alerted Congress functionaries about the vulnerabilities more than a month earlier and highlighted that several were critical. He said there was no official acknowledgement from the party, although vendors handling the websites told him that Congress authorities had been informed.
After waiting for more than a week, he contacted CERT-In, the Indian Computer Emergency Response Team under the Ministry of Electronics and Information Technology (MeitY). CERT-In responded and sought further information before proceeding with due diligence.
The researcher later said a member of the Congress technology team contacted him on X, after which several Congress pages collecting information and donations were disabled.
Congress subsequently told him that the issues had been fixed, although he said CERT-In had not provided formal communication on closure. OpIndia said it had contacted MeitY to ask whether such communication forms part of CERT-In’s standard procedure.
What the researcher claims he found
The researcher alleged that Mahila Congress website vulnerabilities could allow access to OTP responses, user details such as address, age and gender, volunteer networks and profile pictures without proper login protection.
On Gandhi’s website, he claimed registration records could be queried without an account, password, cookie, token or API key.
The report also said weakly protected databases can be targeted by underground data brokers and cybercriminals, who may copy and sell information online.
Despite the alleged vulnerabilities, Congress and Gandhi have not publicly acknowledged the issue, the report said. It also noted that a Congress volunteer website launched in 2021 had faced an earlier data leak and security breach.
Quick Answers
Security expert Shashi reported that personal details, including mobile numbers and records for lakhs of people, were potentially exposed on Rahul Gandhi’s Chhatron Ki Goonj website and other Congress-affiliated platforms without proper login protection. The BJP subsequently accused Rahul Gandhi of playing with students’ futures and exposing them to cybercriminals.
About the Author

Shuddhanta Patra is an Indian journalist with about nine years of experience in covering national politics, geopolitics, defence, diplomacy and international affairs. Her reporting focuses on South As…Read More
Delhi, India, India
September 21, 2026, 10:44 IST
Read More