Premium
This is an archive article published on June 16, 2023

CoWIN data ‘breach’: Probe looks at likely leaks from 11 states

The agency is looking into any potential leaks that could have happened from the databases of these states. While Karnataka and Kerala are learnt to be among the 11 states, there is no information yet on the remaining states.

Data ‘breach’: Probe looks at likely leaks from 11 statesThe alleged CoWIN data leak could impact more than 100 core individuals who have secured vaccinations after signing up through the CoWIN portal (Express Photo)
Listen to this article
CoWIN data ‘breach’: Probe looks at likely leaks from 11 states
x
00:00
1x 1.5x 1.8x

As part of its investigation into the alleged CoWIN data breach, the Indian Computer Emergency Response Team (CERT-In) — the nodal cyber security agency — is in discussions with at least 11 state governments that had developed their own databases during the Covid-19 pandemic and seeded citizens’ personal data including their Aadhaar details, The Indian Express has learnt.

The agency is looking into any potential leaks that could have happened from the databases of these states. While Karnataka and Kerala are learnt to be among the 11 states, there is no information yet on the remaining states.

“Some states had created their full-fledged databases during the pandemic to track things like containment zones and vaccination status of residents. Some health workers in the states may also have had access to that data, which in some cases was stored on local devices. CERT-In has expanded the scope of its investigation into the issue by assessing whether one of these databases was impacted,” said a senior Union government official.

Story continues below this ad

During preliminary discussions, Karnataka and Kerala have indicated that they had created their respective databases during the pandemic to monitor containment zones, the official said.

CERT-In is also coordinating with messaging platform Telegram, where a bot was sharing citizens’ sensitive data, allegedly sourced from the CoWIN database, to ascertain the identity of the person or group behind it.

However, the messaging platform has told the agency that the group that was operating the bot, called ‘hak4learn’, was using a virtual private network (VPN) to access the service, due to which it was difficult to pinpoint their identity or location.

Telegram, which was founded in Russia and is now headquartered in the British Virgin Islands, did not respond to The Indian Express’s queries on the issue.

Story continues below this ad

Earlier this week, following reports that CoWIN data had been breached and was being shared on Telegram through a bot, the health ministry had asked CERT-In to probe the issue and submit a report. CERT-In is expected to share its report with the ministry next week.

The health ministry had said the CoWIN system was “completely safe with adequate safeguards for data privacy” and all reports of a breach were “without any basis and mischievous in nature”.

Rajeev Chandrasekhar, Minister of State for Electronics and IT, had said that CERT-In had reviewed the alleged breach, and the data being accessed by the Telegram bot was from a “threat actor database” which seems to have been populated with previously breached data, which was not related to CoWIN. “It does not appear that the CoWIN app or database has been directly breached,” he had said.

Meanwhile, TMC MP Derek O’Brien is learnt to have filed a complaint with Kolkata’s cyber police, demanding an investigation into the issue. “…there is a notorious conspiracy at play to make available sensitive information to private players through government resources,” he said in his complaint.

Soumyarendra Barik is Special Correspondent with The Indian Express and reports on the intersection of technology, policy and society. With over five years of newsroom experience, he has reported on issues of gig workers’ rights, privacy, India’s prevalent digital divide and a range of other policy interventions that impact big tech companies. He once also tailed a food delivery worker for over 12 hours to quantify the amount of money they make, and the pain they go through while doing so. In his free time, he likes to nerd about watches, Formula 1 and football. ... Read More

Stay updated with the latest - Click here to follow us on Instagram

Latest Comment
Post Comment
Read Comments
Advertisement
Loading Taboola...
Advertisement
Advertisement