Information · 10 min read · 14 min 20 sec listen · Published 7 May 2026

Aadhaar Details and Phone Number Leaked on Telegram — What You Can Do Legally in India

Someone leaked your Aadhaar and phone details on Telegram? Here's the exact legal approach, applicable BNS sections, and steps to protect yourself.

Aadhaar Details and Phone Number Leaked on Telegram — What You Can Do Legally in India
One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.

Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.

Aadhaar Details and Phone Number Leaked on Telegram — What You Can Do Legally in India

Sneha Iyer, a nineteen-year-old resident of Gomti Nagar, Lucknow, first realised something was wrong in early March 2025. A stranger on Telegram had somehow obtained her mobile number, traced the SIM to her mother's Aadhaar card, and was actively circulating the family's personal information across multiple Telegram groups. The stranger had mistaken Sneha for someone else entirely — a friend of a mutual contact — and rather than verifying his error, he chose to publicise the details as a form of intimidation.

Sneha first went to a general practitioner, who told her to file an online cyber complaint and wait. Weeks passed. Nothing meaningful happened. Frustrated and genuinely alarmed, because the leaked data included her mother's Aadhaar number and residential address, she was referred to Advocate Sudhir Rao. The approach shifted entirely. A formal cyber complaint was filed with the Lucknow Cyber Crime Cell, supported by preserved screenshots and a documented chain of evidence. Simultaneously, a legal notice was dispatched to the offending individual through the contact details his own friend had voluntarily provided. The Cyber Crime Cell took cognizance promptly once the complaint was properly structured with specific statutory references. The circulation stopped, and the matter moved toward resolution within a few weeks — an outcome the initial, unstructured approach hadn't come close to achieving.

Advice in Such Cases

Consult with Lawyer / Advocate: The very basic and important step to start is talk to a Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.

Preserve all digital evidence immediately: Take timestamped screenshots of every Telegram message, group post, or chat showing your personal data being shared. Don't rely on memory — courts and cyber cells require concrete documentary proof. Store copies on a separate device or a secure cloud account.

Do not confront the individual directly: Any direct communication with the person leaking your data, especially through informal channels, can complicate the legal record. Let your advocate handle all contact, whether through a formal legal notice or otherwise.

File a structured cyber complaint: Report the matter on the National Cyber Crime Reporting Portal (cybercrime.gov.in) and simultaneously approach your local Cyber Crime Cell. A complaint that cites the correct statutory provisions is far more likely to receive prompt attention than a vague grievance. Frankly, matters involving Aadhaar data and telephone subscriber information carry specific procedural requirements and evidentiary standards that advocates who regularly handle cyber cases are well-positioned to address — general practitioners may not be familiar with the technical specifics that cyber cells expect in such complaints.

Applicable Sections of Law

This matter falls squarely within the criminal domain, attracting multiple provisions under the Bharatiya Nyaya Sanhita, 2023 (BNS) and the Information Technology Act, 2000 (IT Act), which continues to operate alongside the BNS for cyber offences:

  • Section 351 BNS (Criminal Intimidation): Applies where a person threatens to publish private information to cause alarm, even without an explicit demand.
  • Section 318 BNS (Cheating): Relevant where the act involves obtaining or using personal data through deceptive means.
  • Section 66C, IT Act, 2000 (Identity Theft): Covers fraudulent use of another person's electronic signature, password, or unique identification feature — which includes Aadhaar-linked data.
  • Section 66E, IT Act, 2000 (Violation of Privacy): Directly applicable where a person intentionally captures, publishes, or transmits the private information of another person without consent.
  • Section 43A, IT Act, 2000: Imposes civil liability on a body corporate that negligently handles sensitive personal data — useful if any platform or service provider is implicated.

Punishment and Penalties

Now, before you act, understand what the law actually prescribes here. The penalties aren't trivial.

  • Section 66C, IT Act: Imprisonment up to three years and fine up to Rs. 1,00,000. Cognizable, non-bailable.
  • Section 66E, IT Act: Imprisonment up to three years or fine up to Rs. 2,00,000, or both. Cognizable, bailable.
  • Section 351 BNS: Imprisonment up to two years, or fine, or both. Bailable and cognizable depending on the nature of threat.
  • Aadhaar Act, 2016, Section 29 and Section 38: Unauthorised use or disclosure of Aadhaar identity information attracts imprisonment up to three years and fine up to Rs. 10,000 for an individual. Non-compoundable.

Jurisdiction — Where to File the Case

Cyber offences under the IT Act may be reported at the Cyber Crime Cell of the police station having territorial jurisdiction over the place where the victim is located. In this type of case, where Sneha resided in Gomti Nagar, Lucknow, that was the appropriate Cyber Crime Cell. Complaints may also be filed on the National Cyber Crime Reporting Portal, which routes the complaint to the jurisdictionally competent unit. The jurisdictional Magistrate's Court also has cognizance over complaints filed under the IT Act. And here's the thing: getting jurisdiction right from the outset matters. A complaint filed at the wrong station can be delayed or transferred, losing valuable time when data is actively being circulated.

What if Police Refuse to File FIR?

Refusal by police to register a complaint in cyber matters isn't uncommon. Here's what you can do:

  • Submit a written complaint to the Superintendent of Police (Cyber) under Section 173(4) BNSS, requesting directions to the concerned station to register the FIR.
  • File a private complaint directly before the jurisdictional Magistrate under Section 175(3) BNSS — the Magistrate can direct the police to investigate.
  • Approach the High Court by way of a writ petition under Article 226 of the Constitution, seeking a writ of mandamus directing police to register the FIR — this is particularly effective when inaction is deliberate.
  • File a detailed written complaint on cybercrime.gov.in and retain the acknowledgment number; this creates a formal record that supports subsequent legal steps if the local police remain unresponsive.

Rights of the Accused

Even as a victim pursuing legal action, it helps to understand the rights of the person you're proceeding against. This shapes your strategy. And here's the thing: knowing these rights prevents surprises during proceedings.

  • The accused has the right to remain silent and cannot be compelled to incriminate himself under Article 20(3) of the Constitution.
  • The right to legal representation is guaranteed under Article 22 of the Constitution — the accused will have counsel opposing you.
  • The accused must be produced before a Magistrate within 24 hours of arrest under Article 22(2) and Section 57 BNSS.
  • The accused is entitled to a copy of the FIR and must be informed of the grounds of arrest under Section 47 BNSS.
  • The right against double jeopardy under Article 20(2) applies — charges must be framed with precision to avoid procedural challenges.

Bail Provisions

Section 66E of the IT Act is bailable in nature, meaning the accused may be released on bail as a matter of right. Section 66C is non-bailable — police or court discretion applies. Regular bail may be sought under Section 480 BNSS before the Magistrate or under Section 483 BNSS before the Sessions Court. Anticipatory bail under Section 482 BNSS is available where the accused apprehends arrest. Typical bail conditions include surrender of passport, no contact with the complainant, and periodic appearance before the investigating officer. From a victim's perspective, your advocate can oppose bail or seek stringent conditions, particularly no-contact orders. That's a tactical step often overlooked without domain-specific guidance.

Quashing of FIR / Case

Sometimes the accused approaches the High Court seeking quashing of the FIR under Section 528 BNSS, which preserves the High Court's inherent powers. Grounds typically advanced include absence of prima facie offence, abuse of legal process, or that the dispute is purely civil in nature. In cases of genuine data leak and threat to publish personal information, quashing petitions are difficult to sustain, particularly where documentary evidence of publication or threatened publication exists. But if the parties reach a genuine settlement before trial, that can be placed before the High Court as a ground for quashing where the offence is compoundable.

Aadhaar Details and Phone Number Leaked on Telegram — What You Can Do Legally in India

If You Are the Victim

Act fast. Data spreads faster than most people realise, and every hour of delay matters.

  • Immediately take timestamped screenshots of all Telegram posts, messages, or groups where your data appears — do this before reporting, because the offender may delete content once they know action is being taken.
  • File a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in) and note the complaint number for follow-up.
  • Request your telecom operator in writing to flag your number for unusual data access activity — keep a copy of this request.
  • Report the Telegram channel or group for privacy violation directly through Telegram's in-app reporting mechanism — this creates a platform-level record.
  • Engage an advocate promptly; don't wait to see whether the situation "resolves itself." Data, once circulated, spreads fast.

Documents You Must Keep Ready

  • Your Aadhaar card and the Aadhaar card of the family member whose details were leaked (mother's, in a typical case like this)
  • Screenshots of Telegram messages, posts, or groups showing your personal data — with visible timestamps and usernames
  • Your mobile number's subscriber information or telecom bill, establishing that the SIM is registered in your family member's name
  • Any written or digital communication from the offending individual or through mutual contacts
  • Acknowledgment receipt of complaint filed on cybercrime.gov.in
  • Contact details of the offender, if obtained through legitimate means (such as a mutual contact voluntarily sharing them)
  • A written statement from the friend who shared the offender's screenshots — this can serve as a witness statement
  • Any prior communication showing you had no relationship or interaction with the offender

What Evidence Is Required?

  • Primary digital evidence: Timestamped screenshots of Telegram posts or messages showing your Aadhaar number, address, or phone number being shared — exported and stored securely.
  • Device-level evidence: Screen recordings where possible, capturing the Telegram interface with the offender's username and the content visible simultaneously.
  • Witness statement: A written account from the mutual friend who first showed you the screenshots and who can confirm the offender's identity.
  • Telecom subscriber data: Call Detail Records (CDR) or subscriber verification from the service provider, obtained through official channels, linking the offender's number to their identity.
  • Aadhaar records: UIDAI authentication logs, if obtainable, showing any unauthorised access or query against the linked Aadhaar.
  • Platform communication logs: Telegram group membership records or forwarded message metadata, which cyber forensics can extract during investigation.

How the Police Behave in Such Cases

Cyber Crime Cells across Indian cities vary considerably in responsiveness. Make no mistake — a complaint that arrives without proper statutory references often sits in a queue. Officers may initially suggest that because no "direct threat" was made, the matter lacks urgency. This is incorrect as a matter of law. Section 66E of the IT Act and Section 351 BNS don't require an explicit demand or threat for the offence to be made out. A properly drafted complaint citing these provisions, backed by organised evidence, typically receives faster attention. Persistence and a formal record of all communications with the cell are important tactical tools.

  • Week 1-2: File complaint on cybercrime.gov.in and at local Cyber Crime Cell; secure all evidence; issue legal notice to offender through advocate.
  • Week 2-4: Cyber Crime Cell acknowledges complaint; preliminary inquiry begins; telecom data may be requisitioned by police.
  • Month 1-3: FIR registered (if not done at complaint stage); formal investigation commences; offender may be summoned or arrested.
  • Month 3-6: Chargesheet filed before jurisdictional Magistrate under Section 193 BNSS within the statutory period.
  • Month 6-12: Magistrate takes cognizance; charges framed; trial proceedings begin.
  • Year 1-3: Evidence recorded; arguments heard; judgment delivered at trial court level.
  • Post-judgment: Appeal to Sessions Court or High Court, if required, under applicable provisions of BNSS.

How Long Will the Investigation Take?

In cyber cases of this nature, the initial investigation, including identification of the offender through telecom data and digital forensics, typically takes between 30 and 90 days once an FIR is formally registered. Chargesheet filing under Section 193 BNSS must occur within the statutory period prescribed — failing which, the accused becomes entitled to default bail. So there's a reason your advocate will push for FIR registration rather than letting the matter linger at the complaint stage. An unregistered complaint has no chargesheet deadline attached to it. That difference

Was this article useful?

/5 (0 ratings)