Personal data of thousands of people in India has been leaked from a government server which includes their name, mobile number, address and Covid-19 test result, and this information can be accessed through online search.
The leaked data has been put on sale on the Raid Forums website where cyber criminal claims to have the personal data of over 20,000 people.
The data put on Raid Forums shows the name, age, gender, mobile number, address, date and result of the Covid-19 report of these people.
Cyber Security researcher Rajshekhar Rajaharia also tweeted that personally identifiable information (PII) including name and Covid-19 results are made public through a content delivery network (CDN).
He said that Google has indexed lakhs of data from the affected system.
"PII including Name, MOB, PAN, Address etc of #Covid19 #RTPCR results & #Cowin data getting public through a Govt CDN. #Google indexed almost 9 Lac public/private #GovtDocuments in search engines. The patient's data is now listed on #DarkWeb. Need fast deindex," Rajaharia said in his tweet.
PII including Name, MOB, PAN, Address etc of #Covid19 #RTPCR results & #Cowin data getting public through a Govt CDN. #Google indexed almost 9 Lac public/private #GovtDocuments in search engines. Patient's data is now listed on #DarkWeb. Need fast deindex#Infosec @IndianCERT pic.twitter.com/LgQxZZi8T6— Rajshekhar Rajaharia (@rajaharia) January 19, 2022
An email query sent to the Ministry of Electronics and IT did not elicit any reply.
The sample document shared on Raid Forums shows that the leaked data was meant for upload on the Co-WIN portal.
The government has heavily relied on digital technologies in terms of controlling and creating awareness about the Covid-19 pandemic as also its vaccination programme. Several government departments mandate people to use the Aarogya Setu app for Covid-19 related services and information.
Rajaharia in a follow-up tweet on January 20 said that he is not reporting any vulnerability in this incidence but cautioning people to remain alert from fraud calls, offers related to Covid-19, etc that they may get as their data is being sold on the dark web.
Data sold on the dark web is often exploited by cybercriminals and fraudsters for various kinds of frauds.