Health Ministry, Security Researchers reject CoWin data breach


By MYBRANDBOOK


Health Ministry, Security Researchers reject CoWin data breach

After news of the hack spread on the internet, the Health Ministry and security researchers have denied the breach of COVID-19 vaccination data of 150 million Indians. On June 10, Data Leak Market was selling a database of COVID-19 vaccination in India for $800. The data included vaccination of 150 million people including name, Aadhaar number, and location. “We are not the original leakers of data. We are the reseller,” the website read. The data leak allegedly happened on the CoWin portal, which is used by users and the government for vaccination. However, the health ministry and security researchers have ruled out the possibility of such a hack.

 

RS Sharma, Head-Co-WIN portal, said, "Our attention has been drawn towards the news circulating on social media about the alleged hacking of the Co-WIN system. In this connection we wish to state that Co-WIN stores all the vaccination data in a safe and secure digital environment. No Co-WIN data is shared with any entity outside the Co-WIN environment. The data being claimed as having been leaked, such as geo-location of beneficiaries, is not even collected at Co-WIN. The news prima facie appears to be fake. However, we have asked the Computer Emergency Response Team of MeitY to investigate the issue."

 

Rajshekhar Rajaharia, an independent security researcher, also said that the Co-WIN portal was not hacked. “Some fake Dark Leak Market is claiming to sell data of 150 Million COVID-19 Vaccinated People of India. It's completely fake and a Bitcoin scam.” He further explained that the website has been posting leaked documents, which are fake. The reportedly leaked documents the site posted include SBI YONO, which was never hacked, he pointed out. It was also selling Mobikwik user data, which Rajaharia said, are not available on the dark web.

 

However, Apar Gupta, who runs Internet Freedom Foundation, a digital rights organisation, said in a tweet that it is important for Indian Computer Emergency Response Team to step in. "This is a critical data leak. It must be fairly and independently verified, the issue causing it and accountability must be fixed. We must resist the temptation to issue a blanket denial. Investigate, verify, please!," he tweeted.

 

Srinivas Kodali, a digital rights researcher, tweeted, "How does one establish if there was a cyber security breach? Cyber forensics. Who is responsible for this? What if it is a fake alert? Still, one has to investigate it to confirm it."

 E-Magazine 
 VIDEOS  Placeholder image

Copyright www.mybrandbook.co.in @1999-2024 - All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.
Other Initiatives : www.varindia.com | www.spoindia.org