Moneycontrol PRO
HomeNewsTechnologyNo leak of users' data from CoWIN portal, adequate safety measures in place: Govt

No leak of users' data from CoWIN portal, adequate safety measures in place: Govt

A government source said all application programming interfaces (API) associated with CoWIN are being looked over, and the Health Ministry is expected to post a clarification in this regard.

June 12, 2023 / 17:14 IST
The personal information of every citizen, who used the app can be seen using a Telegram bot where you simply need to enter the phone number to see the details. (Image: Shutterstock)

The government on June 12 said that claims of data breach from the CoWIN portal are baseless and mischievous in nature.

"CoWIN portal of the Health Ministry is completely safe with adequate safeguards for data privacy. Furthermore, various security measures are in place on the CoWIN portal. Only OTP authentication-based access to data is provided. All steps have been taken and are being taken to ensure the security of the data in the CoWIN portal," said a press release.

In a tweet, Union Minister of State for Electronics and Information Technology Rajeev Chandrasekhar said that the matter had been reviewed by nodal cybersecurity body CERT-IN. According to him, the data that was being accessed by the bot was from a threat actor database that was populated “with previously breached/stolen data from the past”. He maintained that it does not appear that the CoWIN app or database has been directly breached.

Regarding claims of a Telegram BOT accessing users’ personal data, the government clarified that without OTP vaccinated beneficiaries’ data cannot be shared with any BOT. “Only Year of Birth (YOB) is captured for adult vaccination but it seems that on media posts it has been claimed that BOT also BOT mentioned the date of Birth (DOB),” the release said. There is no provision to capture the address of the beneficiary, it added.

The development team of CoWIN has confirmed that there are no public APIs where data can be pulled without an OTP. In addition to the above, there are some APIs which have been shared with third parties such as ICMR for sharing data. It is reported that one such API has a feature of sharing the data by calling using just a mobile number of Aadhaar. However, even this API is very specific and the requests are only accepted from a trusted API which has been white-listed by the Co-WIN application, the release said.

COVID-19 Vaccine

Frequently Asked Questions

View more
How does a vaccine work?

A vaccine works by mimicking a natural infection. A vaccine not only induces immune response to protect people from any future COVID-19 infection, but also helps quickly build herd immunity to put an end to the pandemic. Herd immunity occurs when a sufficient percentage of a population becomes immune to a disease, making the spread of disease from person to person unlikely. The good news is that SARS-CoV-2 virus has been fairly stable, which increases the viability of a vaccine.

How many types of vaccines are there?

There are broadly four types of vaccine — one, a vaccine based on the whole virus (this could be either inactivated, or an attenuated [weakened] virus vaccine); two, a non-replicating viral vector vaccine that uses a benign virus as vector that carries the antigen of SARS-CoV; three, nucleic-acid vaccines that have genetic material like DNA and RNA of antigens like spike protein given to a person, helping human cells decode genetic material and produce the vaccine; and four, protein subunit vaccine wherein the recombinant proteins of SARS-COV-2 along with an adjuvant (booster) is given as a vaccine.

What does it take to develop a vaccine of this kind?

Vaccine development is a long, complex process. Unlike drugs that are given to people with a diseased, vaccines are given to healthy people and also vulnerable sections such as children, pregnant women and the elderly. So rigorous tests are compulsory. History says that the fastest time it took to develop a vaccine is five years, but it usually takes double or sometimes triple that time.

View more
Show

In addition, an internal exercise has been initiated to review the existing security measures of CoWIN. CERT-In in its initial report has pointed out that the backend database for the Telegram bot was not directly accessing the APIs of the CoWIN database.

Earlier in the day, an official from MeiTY (Ministry of Electronics and Information Technology), has confirmed the alleged breach of data on the CoWIN platform and told Moneycontrol that a team from the CERT-IN (Indian Computer Emergency Response Team) has initiated an investigation into the matter.

The bot in question, which was publishing this information has been disabled, an official said.

S Gopalakrishnan, CEO of the National Health Authority refused to comment on a query from Moneycontrol in the matter.

First reported by the Malayalam Manorama newspaper, which independently verified the leak, the personal information of every citizen, who used the app can be seen using a Telegram bot where you simply need to enter the phone number to see the details.

Reportedly, the Secretary of the Union Health Ministry, Rajesh Bhushan was one of the victims, along with several prominent names such as CoWIN Chairman Ram Sewak Sharma, Kerala Health Minister Veena George, Congress General Secretary KC Venugopal, Union Minister of State Meenakshi Lekhi, journalists Rajdeep Sardesai and Barkha Dutt, and more.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Ayushman Kumar
Ayushman Kumar Covers health and pharma for MoneyControl.
Aihik Sur covers tech policy, drones, space tech among other beats at Moneycontrol
Rohith Bhaskar
first published: Jun 12, 2023 03:50 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347
CloseOutskill Genai