comScore
  • TMC's Derek O'Brien files FIR over CoWin data breach report

    National
    TMC's Derek O'Brien files FIR over CoWin data breach report

    Trinamool Congress MP Derek O'Brien has filed a case over reports of a leak of confidential and sensitive data contained in the CoWIN portal...


    Digital Desk: Trinamool Congress MP Derek O'Brien has filed a case over reports of a leak of confidential and sensitive data contained in the CoWIN portal, according to reports. He stated that the reported data breach was the result of a "deep-rooted conspiracy" involving "high-ranking public servants, government officials, and other unknown individuals." He claimed that the breach "directly threatens the functioning of the various organs of the different governmental organizations."


    "A deep-rooted conspiracy is at work, involving high-ranking public servants, government officials, and other unknown persons who have divulged sensitive data concerning citizens and, in the process, allowed personal data theft to private entities," the TMC leader said in his complaint to Lalbazar Cyber Police Station in Kolkata. 


    Also Read : Defence Ministry approves state-of-the-art armed predator drones deal with USA


    "The news about yesterday's data breach on Telegram is only the tip of the iceberg; it remains to be investigated how far and how deep such data has been divulged to private entities, both within India and to foreign players," it added. 


    Earlier this week, some claimed that data from the CoWIN portal, which was designed to assist the registration and scheduling of Covid vaccines, was publicly available online. In response to the allegations, Union Minister of State for Electronics and Information Technology Rajeev Chandrasekhar stated that a Telegram Bot was displaying CoWIN app details when phone numbers were entered.


    "The data being accessed by a bot from a threat actor database, which appears to have been populated with previously stolen data stolen in the past. It does not appear that the CoWin app or database has been directly compromised," the minister said.  


    The Union Health Ministry denied as "mischievous" reports of a data breach on the site, saying the subject has been evaluated by the country's nodal cyber security organisation, CERT-In. The health ministry stated in a statement that there was no evidence for reports suggesting a data breach from the CoWIN portal, which is the repository of all data of beneficiaries who have been vaccinated against Covid.


    "It is clarified that all such reports have no basis and are false. The Health Ministry's CoWIN portal is completely safe, with adequate safeguards for data privacy," it said, adding that security measures on the portal include a web application firewall, frequent vulnerability assessment, and identity and access management. "Only OTP authentication-based data access is available. All measures were implemented and are being taken in order to guarantee the security of the information stored in the CoWIN portal," the ministry added.


    "CERT-In pointed out in its initial report that the backend database for the Telegram bot was not directly accessing the APIs of the CoWIN database. " the statement said. According to the report, certain Twitter users have reported that the personal data of vaccinated individuals is being accessible via a Telegram (online messenger program) Bot. The bot was able to collect individual data by merely submitting the beneficiary's telephone number or Aadhaar number, the ministry said.