Cyber-criminals have allegedly stolen data of thousands of people in India, including health workers, from a government server (that has even been indexed in Google Search), which includes name, mobile number, address and Covid test results.
The data of over 20,000 Indians are available on the Raid Forums website on the Dark Web, and the hacker claims that they are directly coming from a government CDN (content delivery network) server.
The same documents are also available freely on Google Search as "List of Beneficiaries Enrolled for Covid Vaccine" with keywords like RT-PCR results.
"PII including Name, MOB, PAN, Address etc of #Covid19 #RTPCR results & #Cowin data getting public through a Govt CDN. #Google indexed almost 9 Lac public/private #GovtDocuments in search engines. Patient's data is now listed on #DarkWeb. Need fast deindex," cyber security researcher Rajshekhar Rajaharia Rajaharia said in a tweet.
The most pressing concern is that the data of thousands of health workers (available in PDF files) have been exposed online in Google Search that contains PAN numbers, Aadhaar and other personal details like mobile numbers, address, age, gender etc.
The IT Ministry or the Indian Computer Emergency Response Team (CERT-IN) is yet to react to the alleged leak.
"I am not reporting any #Vulnerability here. I am asking people to #Beware for any Fraud #calls/#offers/#treatment etc related to pre/post #Covid19. The data is already up for sale on a #DarkWeb Forum," Rajaharia said in another tweet.
Last year, the Health Ministry and security researchers had denied the breach of Covid-19 vaccination data of 150 million Indians, after news of the hack spread online.
The data leak allegedly happened on the CoWin portal, which is used for vaccination.
However, regarding the data leak, the Ministry of Health & Family Welfare issued a statement on its Twitter handle.
The post read: "Regarding data leak from CoWIN: We are getting the matter examined. However, prima facie it appears that the alleged leak is not related to Co-WIN as we neither collect any information on address or the COVID19 status of beneficiaries."
#COVID19Update— Ministry of Health (@MoHFW_INDIA) January 21, 2022
Regarding data leak from #CoWIN: We are getting the matter examined. However, prima facie it appears that the alleged leak is not related to Co-WIN as we neither collect any information on address or the #COVID19 status of beneficiaries.@PMOIndia @mansukhmandviya