UP State Tax officials are probing alleged manipulation of 22 employees’ confidential records, with password resets, login logs and IP addresses central to determining who did it.

Hack or Insider Misuse? 22 UP Employees’ Records Allegedly Altered on Government Portal

The420 Web Correspondent
8 Min Read

Uttar Pradesh’s State Tax Department is investigating suspected tampering with the online service records of 22 employees after adverse remarks allegedly appeared in annual confidential entries without the knowledge of the officers whose accounts were used.

The affected records relate to employees in the Ghaziabad zone and concern annual entries for 2024-25 on the Manav Sampada human resource management portal. Some employees were allegedly marked with adverse remarks, while questions were even raised over the integrity of certain staff members.

The consequences were not merely administrative.

According to the initial report, promotions of three employees were affected, while financial progression benefits for some others also came under threat because of the disputed entries.

The department has ordered an inquiry, but the central question remains unresolved: was the portal externally compromised, or did someone with internal or privileged access manipulate the records?

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

Password Resets Put Insider Access Under the Scanner

The affected employees have alleged that passwords belonging to authorised officers were reset before the disputed entries were made.

Those officers have reportedly denied entering the adverse remarks themselves. Employees suspect that a master administrator or another higher-level login may have been used to reset credentials and gain control of the accounts.

That allegation is significant because it changes the nature of the investigation.

If an unknown outsider defeated the portal’s security controls and entered the system, the incident could amount to an external cyber intrusion.

But if an administrator or another authorised user misused legitimate privileges, the case would look more like an insider attack or privileged-access abuse.

The two scenarios leave different digital trails.

Investigators will therefore need to determine exactly which user IDs performed the alterations, when passwords were changed and which accounts were active at the relevant time.

What Do IP Addresses, System Logs and Admin Rights Reveal?

A system log is essentially a digital record of activity inside a computer system.

Depending on how a portal is configured, logs can record when someone logged in, which account was used, what action was performed and sometimes which device or network initiated the request.

An IP address is a numerical identifier associated with an internet connection.

Investigators can use it as one clue to determine which network was used to access an account. But an IP address alone does not automatically identify the individual sitting behind a device.

Office networks may be shared by many users. Mobile connections can change IP addresses. VPNs and other technologies can also obscure where an internet session originated.

That is why investigators normally need to correlate IP records with login times, password-reset history, device information and the exact account activity.

Administrative privileges are another important concept.

An ordinary user may be allowed to view or update only limited information. An administrator can have broader powers, such as managing accounts, resetting passwords or modifying system settings.

If such elevated privileges are misused, a person may not need to technically “hack” anything at all.

Why ACR Tampering Can Damage an Employee’s Career

Manav Sampada is an electronic human resource management system developed and managed in Uttar Pradesh with the National Informatics Centre. The UP portal is used for government employees’ service records and other HR functions.

One of those functions involves Annual Confidential Reports, or ACRs.

These reports record assessments of a government employee’s performance and conduct and can influence promotions and other service benefits.

NIC’s Manav Sampada documentation shows that the ACR process can involve an employee, reporting officer, reviewing officer and accepting authority, with different stages of submission and assessment.

That means an unauthorised adverse remark is not comparable to someone casually editing a profile field.

It can potentially affect an employee’s professional record for years.

The State Tax Department itself has previously issued instructions concerning employees’ annual entries through Manav Sampada, showing that the portal is embedded in its official personnel-management process.

This Is Not the Only Manav Sampada Data Integrity Controversy

Another controversy involving Manav Sampada emerged in Agra this week, although it appears to involve a different alleged method.

After authorities ordered salary deductions against 105 education department employees found absent during inspections, verification reportedly discovered that eHRMS identification codes entered for 20 teachers did not correspond to genuine Manav Sampada records.

That case does not establish any connection with the State Tax Department incident.

But both episodes underline the same wider concern: digital government systems are only as reliable as the identity, access and audit controls surrounding the data entered into them.

When personnel decisions depend on electronic records, manipulation of an account, employee code or confidential entry can have consequences similar to falsifying an official paper service book.

Digital Evidence May Decide Whether an FIR Follows

UP State Tax Commissioner Dr Nitin Bansal has confirmed that an inquiry has been ordered and said the possibility of cyber fraud is being examined. An Additional Commissioner in Ghaziabad has been asked to investigate the matter.

Affected employees have demanded registration of an FIR.

Before criminal responsibility can be fixed, investigators will need to reconstruct the sequence of events: who reset the passwords, which IDs were used afterward and whether those sessions correspond with known departmental devices or outside networks.

The Manav Sampada portal currently uses a password login along with a security code and supports OTP-based verification flows. The site states that it is managed by NIC’s UP State Centre while the underlying employee data belongs to the respective state departments.

If the investigation confirms deliberate manipulation, officials will also have to determine whether the original records can be reliably restored and whether similar unauthorised changes were made elsewhere.

For now, describing the episode as a confirmed portal “hack” would go beyond the available evidence.

What is established is more troubling in another way: official personnel records were allegedly changed without the knowledge of the officers whose identities appeared to authorise them.

Finding out whether that happened through stolen credentials, privileged access or an outside breach is now the most important part of the inquiry.

What this means for you: Government employees using official HR portals should treat password-reset alerts, unexpected OTPs and unexplained changes to service records as potential security incidents. Report them immediately so system logs can be preserved before critical evidence is lost.

https://www.linkedin.com/company/policetechnology/

Stay Connected