Moneycontrol PRO
HomeNewsTrendsCERT-In denies CoWIN data breach to Parliament panel, say hackers collated data from different sources

CERT-In denies CoWIN data breach to Parliament panel, say hackers collated data from different sources

A lawmaker part of the committee said government officials denied a data leak from the CoWIN portal, and that the leaked data in public domain was a collation of data bought from several sources.

June 15, 2023 / 20:02 IST
The CERT-In officials said the enquiry in alleged data breach is at a preliminary stage

Officials of the Indian Computer Emergency Response Team or CERT-In as it is commonly referred to on June 15 denied that the CoWIN portal was hacked and information stolen. Instead, they said that the data was collated from several sources.

CoWIN or Covid Vaccine Intelligence Network is a government portal for vaccinations against the COVID-19 disease that holds cross-referenced information on those who registered for the immunisation drive.

Appearing before the parliamentary standing committee on communication and IT, the CERT-In officials said they were probing the issue. Responding to a query from a member of an opposition party, a CERT-In official said that “CoWIN was a breach-proof portal”.

“The CERT-In officials said the enquiry is at a preliminary stage. They (officials) said that the leak of data didn’t happen from the CoWIN portal, saying the data which is being leaked by a bot is a collation of data bought from several sources,” the opposition lawmaker said, on condition of anonymity.

Also read: No leak of users' data from CoWIN portal, adequate safety measures in place: Govt

Terming the claim “unbelievable”, the committee member asked the government officials how bots on the messaging app Telegram got the vaccination details including the names of hospitals involved if the CoWIN portal wasn’t breached.

“The IT officials said that the CoWIN portal only worked via one-time password (OTP), but they failed to answer as to how the details of passports and vaccinations including hospital names were available online,” he added.

The meeting was attended by the secretary, additional secretary and three other officials including scientists from the Ministry Electronics and Information Technology.

Also read: CloudSEK report says hackers don’t have access to CoWin’s backend database

The member said CERT-In officials dodged the questions related to CoWIN, saying the investigation in the matter was at preliminary stage. “They said multiple APIs (application programming interfaces) have been granted access to the CoWIN portal,” he added.

The parliamentary committee met on June 15 to discuss citizens’ data security and privacy.

The health ministry has refuted the claims of data breach from the CoWIN portal as “baseless” and “mischievous in nature”.

"The CoWIN portal of the Health Ministry is completely safe with adequate safeguards for data privacy. Furthermore, various security measures are in place on the CoWIN portal. Only OTP authentication-based access to data is provided. All steps have been taken and are being taken to ensure the security of the data in the CoWIN portal," said a press release.

In a tweet, Union Minister of State for Electronics and Information Technology Rajeev Chandrasekhar said that the matter had been reviewed by CERT-In, the nodal cybersecurity body.

Regarding claims of a Telegram bot accessing users’ personal data, the government clarified that without OTP, vaccinated beneficiaries’ data cannot be shared.

“Only year of birth is captured for adult vaccination but it seems that on media posts it has been claimed that bot also mentioned the date of birth,” the release said. There is no provision to capture the address of the beneficiary, it added.

Ayushman Kumar
Ayushman Kumar Covers health and pharma for MoneyControl.
first published: Jun 15, 2023 08:01 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347
CloseOutskill Genai