Massive Data Breach of Adda Users
Published on:
Share this post

Article Summary
Exam-Focused Notes on Adda Data Breach
Cyber Security Incident:
- Event: Data breach involving Adda, a community and housing society management platform.
- Hacker Alias: ‘Blinkers’.
- Data Compromised: Personal details of over 1.86 million (18.6 lakh) users.
- Type of Data: Owner IDs, names, phone numbers, email addresses, hashed passwords (using the redundant MD5 algorithm).
- Data Size: 145 MB (uncompressed).
- Upload Date: November 23, 2025.
- Cyber Crime Context: Data potentially used for phishing and credential stuffing attacks.
Legislative Framework:
Digital Personal Data Protection (DPDP) Rules, 2025:
- Authority: Notified by the Ministry of Electronics and Information Technology (MeitY).
- Key Features:
- Informed consent requirement for processing personal data.
- Use of data restricted to specified legitimate purposes.
- Obligation for entities to notify users of data breaches.
- Implementation Timeline: Certain provisions operational only after 18 months from notification.
Article Reference:
- Personal data and associated rights categorized under the DPDP Act, 2023.
- Definition of 'personal data breach' as per DPDP.
Company Background: Adda.io
- Founded: 2009 by San Banerjee, Venkat Kandaswamy, and Aashika Sripathi.
- Rebranding: From Apartment Adda to Adda.io in 2019.
- Operations: Facilitates community management activities including visitor management, billing, and facility booking.
- Clientele: Over 3,500 communities in India, serving major developers (e.g., DLF, Prestige).
- Expansion: Clients in the US, Middle East, and Singapore.
Privacy and Surveillance Concerns:
- Rising Popularity: Adoption of gate management apps surged during the COVID-19 pandemic in cities like Delhi and Bengaluru.
- Features: Biometric data collection, service provider listings, chat features among residents.
- Expert Warnings:
- Concerns over workplace and peer surveillance.
- Potential for misuse of data collected through these applications.
- Compliance claims with GDPR and ISO 27001 standards, juxtaposed with risks of data breaches and surveillance.
Conclusion
This data breach incident highlights the urgent need for robust data protection frameworks and compliance with newly enacted laws like the DPDP Rules, contributing to ongoing discussions on privacy rights and cybersecurity in the digital age.
Key Terms & Concepts
| Adda | Community management platform |
| 1.86 million | Number of affected users |
| November 23, 2025 | Date of data upload |
| 145 MB | Size of stolen data |
| DPDP Rules, 2025 | Data Protection legislation |
| Right to Information Act | Related data protection provisions |
| Data Protection Board of India | Regulatory body for data protection |
| GDPR | Data protection regulation compliance |
| ISO 27001 | Information security standard |
| RTI Act amendment | Amendment related to data |
| 3,500 Communities | Adda's client base in India |
| March 2025 | Date of alleged breach |




