A new online tool and Telegram bot called Proxyearth has emerged, enabling anyone to obtain highly sensitive personal information about Indian citizens using only their mobile phone number. Testing by security researchers confirmed that the tool provides accurate and up-to-date details, including full name, father's name, email address, telecom provider, home address, alternate phone numbers, and even Aadhaar card numbers. The service, launched in October 2025, appears to aggregate data from previously breached KYC records, leaked Aadhaar databases, and other state-linked sources, raising significant privacy and security concerns.
The existence of Proxyearth poses a severe threat to national security, as it allows for large-scale surveillance, profiling, and potential targeting of individuals, including government officials, law enforcement, and journalists. The tool's ability to pinpoint exact locations and expose comprehensive identity information highlights the ongoing risks associated with massive data breaches in India and the exploitation of sensitive government and telecom records. Authorities are being urged to investigate the source of the data and take immediate action to mitigate the threat posed by this tool.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
SC Media reported on Proxyearth's ability to expose personal data, including Aadhaar numbers and claimed location information, for Indian citizens via mobile-number lookups. The coverage highlighted the privacy and national-security risks posed by possible insider access or aggregation of previously breached datasets.
Hackread reported that the Proxyearth website and Telegram bot could return highly sensitive personal information and apparent geolocation data for Indian citizens using only a mobile number. Its testing reportedly produced accurate current details, indicating access to large-scale telecom KYC, Aadhaar-linked, or other state-linked datasets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.