Current eventsGovernment InitiativesIndiaNewsPoliticsScience & TechnologySecurity ThreatsSocial IssuesTechnology

ECINET’s Weakest Link Is Not a Proven Hack—it Is Unanswered Control

NEW DELHI, October 7, 2026 — Let us begin with what the evidence does not show. There is no verified public evidence that ECINET has been hacked to alter votes. There is no proof that the Election Commission of India’s public websites can change votes recorded in electronic voting machines. ECINET is an administrative and public-information platform, not an online voting system.

That distinction matters. It also does not excuse what the evidence does show: a critical electoral database has been placed behind software whose control structure, change history, rollback capability and independent audit status remain inadequately explained to the public.

ECINET was officially launched on January 22 as one platform replacing or integrating more than 40 election applications and websites. That can reduce confusion. It also concentrates operational risk. When one system becomes the doorway for voters, candidates, parties and officials, a defect in permissions or workflow can affect more people at once.

The Goa case exposes a functional control failure

The clearest reported failure is not a theoretical cyberattack. It is a software workflow that reportedly prevented lawful correction.

An Indian Express investigation reported that electoral registration officers in Goa found 97 flagged voters eligible to remain enrolled but could not restore them before the final roll because the system lacked the required option. The ERO is the statutory officer responsible for additions and deletions. If that officer reaches a decision but the software cannot execute it, software is no longer merely assisting the legal process; it is obstructing it.

The ECI subsequently said field officers have role-based access according to their statutory powers and that further flexibility would be made operational where required. That response does not answer the central question: why was the missing capability discovered only when eligible citizens needed it, and what audit trail records who requested, denied or delayed the correction?

Centralisation changes the threat model

Election Commissioners Sukhbir Singh Sandhu and Vivek Joshi reportedly raised concerns about the “gradual centralisation” of the electoral-roll database and state officers’ incomplete access. Joshi sought an audit to certify that nobody outside the relevant statutory authorities had credentials to change the database. The ECI disputed the characterization of internal discussions as formal objections and said its systems operate under strict security protocols.

Both statements deserve to be recorded. Neither removes the need for evidence.

Role-based access is only as trustworthy as the role map, approval process and logs behind it. The public still needs answers to simple questions: Which offices can create, approve, reverse and bulk-process a voter record? Can a central administrator override an ERO? Are privileged actions recorded in immutable logs? Who reviews those logs? How quickly can an incorrect batch operation be reversed?

Publishing passwords, source code or exploitable technical detail is not required. Publishing the governance model is.

Form 6 shows weak software change control

The controversy is not limited to access permissions. A Special Intensive Revision declaration was added to the online Form 6 used for voter registration. Two commissioners reportedly questioned whether this could be done without amending the Registration of Electors Rules. After the full Commission met on September 26, it said the ordinary rule-based form would apply outside SIR periods. The declaration was then removed from relevant ECINET screens.

This sequence raises a basic system-integrity question: what approval gate allowed a legally contested field to reach production? Mature public systems require a documented owner, legal approval, testing, version history, deployment authorization and a reversible release. A form affecting electoral eligibility should not change as casually as a marketing webpage.

The privacy story does not add up

ECINET handles services that necessarily involve personal information: voter-registration applications, corrections, identity-linked records, uploaded documents, contact with officials and application tracking. The BLO module also supports field verification and document upload.

Yet the ECINET listings on Google Play and Apple’s App Store state “No data collected,” based on declarations supplied by the developer. That may reflect a narrow platform definition—for example, data passed directly to a government service may be treated differently from analytics collected by the app. But an ordinary voter will read those words literally.

The ECI should publish a service-specific data inventory: every field collected, the legal purpose, whether it is stored, retention period, encryption boundary, processors with access, deletion or correction route, and whether mobile identifiers or telemetry are recorded. A generic assurance that data is secure is not a privacy notice.

The visible websites pass a basic check—but that is not an audit

For this investigation, EnvoyPost retrieved the public home pages of eci.gov.in, voters.eci.gov.in and electoralsearch.eci.gov.in on October 7. All returned HTTP 200 over HTTPS and supplied important browser protections, including HTTP Strict Transport Security, Content Security Policy, anti-framing controls and the nosniff header.

That is good hygiene. It does not test authentication, internal APIs, database permissions, mobile-app storage, incident response or the integrity of voter-roll changes. A header check cannot certify a national electoral platform. Conversely, the absence of a published audit is not proof of a breach.

The ECI says ECINET blocked more than 68 lakh malicious hits on counting day in May. A blocked “hit” is not necessarily a sophisticated attack, and it is not evidence of compromise. The figure shows hostile traffic and the importance of resilience, but without definitions—requests, IPs, signatures, bot events or confirmed intrusion attempts—it cannot measure the severity of the threat.

The promised review needs sunlight

On September 26, the Commission announced a committee led by a senior deputy election commissioner and including an IIT or IIIT expert to “double-check” ECINET’s compliance with election law. The announcement did not state a completion deadline, name the outside expert, define the technical scope or promise publication of the report.

That is not enough for infrastructure governing nearly a billion voters. The review should cover privileged access, least-privilege enforcement, immutable logs, rollback, change approvals, bulk operations, disaster recovery, privacy, third-party dependencies and red-team testing. Its methodology, conflicts disclosures, non-sensitive findings and remediation deadlines should be public.

The conclusion is direct. ECINET has not been publicly proven hacked. But security is not merely the absence of a disclosed breach. It is the ability to prove who can change a voter record, under what law, through which software control, with what record of the action, and how an error is reversed before a citizen loses the vote. On those questions, the ECI still owes India a complete answer.

Featured image: archive photograph of an electronic results display at Nirvachan Sadan in 2009. It does not show ECINET or a current security incident. Election Commission of India/PIB via Wikimedia Commons, GODL-India.

Newsroom

EnvoyPost Newsroom is the collective byline for articles researched, written or substantially edited by the EnvoyPost editorial desk. Editors check material claims against cited sources, distinguish confirmed facts from uncertainty, label archive or representative images, and publish corrections when warranted. Contact: editor@envoypost.in.

Related Articles

Back to top button