7 hrs ago
Congress Alleges ECINET Centralises Voter-List Changes at BJP Headquarters
Congress has accused the Election Commission’s ECINET system of concentrating changes to voter lists at the BJP’s headquarters.
That is an allegation, not a finding established by the reports.
Security researcher Nisarga Adhikary had reported possible weaknesses in the system to the Election Commission and CERT-In.
One reported weakness could reveal election officials’ names and phone numbers.
Another could let information sent through the app be read or changed.
CERT-In said one issue had been fixed and work on other concerns was continuing, but did not say when the fix happened.
Other reports raised questions about whether local officials could access voter-list data and described problems with the portal in West Bengal appeals.
The Election Commission said a committee would review ECINET.
Congress leader Ramesh alleged ECINET was designed to centralise voter-list additions and deletions at BJP headquarters in New Delhi.
Security researcher Nisarga Adhikary reportedly alerted the Election Commission and CERT-In to ECINET vulnerabilities on July 8, 2026.
One reported flaw could expose election officials’ names and mobile numbers without login or CAPTCHA; another could allow app data to be read or altered in transit.
CERT-In said one vulnerability had been fixed and work on the remaining concerns was under progress, but did not specify when the fix was made.
Separate reports described concerns about officials’ access to electoral-roll data and problems with ECINET in West Bengal appeal tribunals; the Election Commission said it would review the system.
- Who
- Congress leader Ramesh, security researcher Nisarga Adhikary, the Election Commission and CERT-In.
- What
- Congress alleged ECINET centralises voter-list changes; reports also detailed security vulnerabilities and concerns about access to the electoral-roll database.
- Where
- The allegation concerns BJP headquarters in New Delhi and the Election Commission’s ECINET system; tribunal-related portal problems were reported in West Bengal.
- When
- Adhikary reportedly notified the agencies on July 8, 2026; CERT-In responded on October 6, according to one report.
- Why
- The reports raised concerns about cybersecurity, access to voter-roll data, and the handling of voter-list appeals.
Critics’ concerns
Reported agency and commission actions
Centralisation of voter-list changes
Critics’ concerns
Ramesh alleged ECINET was designed to centralise additions and deletions at BJP headquarters; other reporting described concerns that local electoral officers might lack database access.
Reported agency and commission actions
The articles do not provide a direct response from the BJP or Election Commission to Ramesh’s centralisation allegation. The Election Commission said a committee would review ECINET.
Security vulnerabilities
Critics’ concerns
Adhikary reported that a server could expose election officials’ contact details and that data in the app might be read or altered in transit.
Reported agency and commission actions
CERT-In said the concerned organisation had confirmed one vulnerability was fixed and that work on other concerns was under progress. The reported response did not specify when the fix occurred.
Portal use in voter appeals
Critics’ concerns
Judges hearing appeals in West Bengal reportedly cited missing portal functions and problems digitising physically submitted appeals, warning of possible injustice to citizens.
Reported agency and commission actions
The articles report that the Election Commission announced a review of ECINET, but do not state that it responded specifically to the tribunal judges’ complaints.
Key facts
- System
- ECINET, including the Election Commission’s voter-services website and application
- Researcher
- Nisarga Adhikary
- Reported notification date
- July 8, 2026
- CERT-In response
- One vulnerability was reported fixed; remaining concerns were described as under progress
- Reported server vulnerability
- Could reveal election officials’ names and mobile numbers without login or CAPTCHA
- Reported app vulnerability
- Could potentially allow data to be read or altered in transit
- Election Commission review
- A committee led by a senior deputy election commissioner, with an independent technical expert, was announced to review ECINET
- West Bengal tribunal concerns
- Judges reported missing or inadequate portal functions affecting appeals, notices, hearings and records
Quotes
Jairam Ramesh
Congress leader commenting on ECINET and the Election Commission.
“A leading daily reports this morning that on July 8, 2026 a security researcher had brought several flaws in ECINET to the attention of the Election Commission.”
telegraphindia.com
“It is becoming abundantly clear that ECINET was designed to centralise all deletions/additions from BJP HQs in New Delhi.”
telegraphindia.com










