• Wion
  • /India News
  • /CoWIN leak: Indian govt refutes Covid vaccine portal data breach reports, orders probe

CoWIN leak: Indian govt refutes Covid vaccine portal data breach reports, orders probe

CoWIN leak: Indian govt refutes Covid vaccine portal data breach reports, orders probe

CoWIN

The Indian government refuted media reports of a major data breach in the Covid vaccination portal CoWIN. Issuing a statement, the Union Health Ministry said, "These reports allege a breach of data from the Co-WIN portal of the Union Health Ministry, which is the repository of all data of beneficiaries who have been vaccinated against Covid."

“Certain posts on the social media platform Twitter have claimed using a Telegram (online messenger application) BOT, the personal data of individuals who have been vaccinated is being accessed. It is reported that the BOT has been able to pull individual data by simply passing the mobile number or Aadhaar number of a beneficiary,” the statement said.

The ministry asserted that such reports are without any basis and are mischievous.

Add WION as a Preferred Source

“Co-WIN portal of the Health Ministry is completely safe with adequate safeguards for data privacy. Furthermore, security measures are in place on the Co-WIN portal, with Web Application Firewall, Anti-DDoS, SSL/TLS, regular vulnerability assessment, Identity & Access Management etc. Only OTP authentication-based access of data is provided,” the statement further said.

The ministry also said that without a One-Time-Password (OTP), vaccinated beneficiaries’ data cannot be shared with any BOT.

The health ministry also requested the Indian Computer Emergency Response Team (CERT-In) to look into this issue and submit a report. In addition, an internal exercise has been initiated to review the existing security measures of CoWIN.

CERT-In in its initial report has pointed out that the backend database for the Telegram bot was not directly accessing the APIs of the CoWIN database.

What did the reports say?

Earlier on Monday, a section of the Indian media reportedthat the personal details of those registered to CoWINwere available on the messaging platform Telegram. According to a report by The News Minute, a Telegram bot hadbeen giving away the details of people who registered for vaccination including their names, date of birth, phone numbers, and other details provided at the time of registration, such as passport or Aadhar numbers among others.

As per a report by Kerala-based Malayala Manorama, if the mobile number of a person was entered, the above details were provided as a reply in an instant by Telegram. The details could be accessed even if the Aadhar number was entered instead of the mobile number, the report added.

Passport numbers of people who updated CoWINfor travelling abroad were leaked. The Manorama report also said that sincemany members of a family registered themselves on the portal under a single phone number, their details were also available on Telegram.

TMC’s Saket Gokhale alleges data breach of politicians, journalists

The data breach also leaked the details of many prominent politicians and journalists in India. In a Twitter thread, Trinamool Congress (TMC) leader Saket Gokhale shared screenshots of the details of politicians and journalists being leaked.

"There has been a MAJOR data breach of Modi Govt where personal details of ALL vaccinated Indians including their mobile nos., Aadhaar numbers, Passport numbers, Voter ID, Details of family members etc. have been leaked & are freely available," Gokhale tweeted and slammed the central government of not being aware of the leak and not informing citizens about the same.

"Who has the Modi Govt given access to sensitive personal data of Indians incl Aadhaar & Passport nos. which enabled this leak?" the TMC leader added and called the breach "a matter of serious national concern."

WATCH WION LIVE HERE

You can now write for wionews.com and be a part of the community. Share your stories and opinions with us here.