HomeCyber Security News9 Lakh PII Indian COVID-19 Patient's Data is now Listed on Search...

9 Lakh PII Indian COVID-19 Patient’s Data is now Listed on Search Engines

-

Key Takeaways
  • Indian security researcher discovered a misconfiguration issue in Indian COVID-19 data portals leaking PII of 9 Lakh citizens.
  • Data from Haryana's COVID websites was exposed, allowing unauthorized access to personal details and test results.
  • Authorities have patched the vulnerability, but the leaked data is available on search engines and dark web, posing a risk of exploitation and scams.

Cyber Security Threat: This month, an Indian security researcher has spotted a misconfiguration issue in one of Indiaโ€™s COVID-19 data portals, that leaked the PII of over 9 Lakh citizens!

The easy-to-exploit vulnerability was now patched by the relevant authorities, after being responsibly disclosed. While itโ€™s secured now, the government has not informed the public of this incident yet and is not immediately acting on the public display of concerned URLs. Itโ€™s found that the data was stolen, and is made available for free in several dark web marketplaces.

Leakage of Indiansโ€™ COVID-19 Data

For a long, weโ€™ve seen numerous instances of cloud databases leaking senstive data stored in them due to improper configuration. While itโ€™s a shame for the server managers, leaking such databases due to very basic issues is more concerning. And it just happened with Indian authorities, who left personally identifiable data of over 20,000 citizens in wild.

As seen and reported by Sourajeet Majumder, an Indian security researcher, the COVID websites of Haryana โ€“ Covid Sample Report Portal and the Covid-19 Sero Survey Portal โ€“ are tagged as the primary culprits here.

However, another Indian security researcher, Rajshekhar Rajaharia, raised the issue on Twitter. As per his statement, he isnโ€™t reporting any Vulnerabilities. He also warned people to stay alert on the lookout for any pre/post Covid19-related fraud calls, offers, or treatment.

The first site is used for storing the COVID-19 testing details uploaded by all COVID-19 laboratories (public or private), for direct monitoring of Haryanaโ€™s Chief Minister. And the second site is for estimating and monitoring the trends of SARS-CoV infectionโ€™s seroprevalence in Haryanaโ€™s high burden cities.

The data of 9 lakh Indian COVID-19 patients has been leaked on a search engine.

Second, there are some publicly accessible Google Indexed CDN pages of Govt. sites where the data can be accessed.

They were said to have basic issues, that leaked the data of thousands of people to anyone with no authorized privileges. According to Majumder, a simple Forced Browsing/Direct URL access attack has led him to access the secured records within, and even modify them as desired!

Explaining further, he said any unauthorized person can visit the website to view a list of all positive patients from Haryana, along with their mobile number, age, gender, residential address, test results, etc. In total, there were over 2,68,126 patients listed in them, with more being updated in real-time.

Apart from accessing, the perpetrator can edit the records too, like changing the test results to positive or negative, deleting records, changing sample IDs, and viewing or adding related lab in-charge. He disclosed this responsibility to the concerned authority on December 14th last year, which triggered the authority to pull down the site for a couple of hours.

Thanking on his report, the authority has not responded to further questions like any traces of exploitation of the vulnerability in wild. Two weeks after, the site was restored with the vulnerability fixed. While itโ€™s secured now, a more concerning part is the Google indexing of these sitesโ€™ URLs in its results.

This can let anyone check the sensitive data thatโ€™s restricted for administrators! Also, weโ€™ve found the dump that Majumder stated is now being available for free in one of the popular database forums, letting anyone with basic knowledge of such groups have their hands on it!

Note
As a result, whether you were a part of the leak or not, we advise you to be cautious of any potential scams that may come your way. These could be pre/post-COVID-19 fraud calls, offers, or treatments, among other things.
Mukesh Bhardwaj
Mukesh Bhardwajhttps://itechhacks.com
Editor - An aspiring Web Entrepreneur and avid Tech Geek. He loves to cover topics related to iOS, Tech News, and the latest tricks and tips floating over the Internet.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST