Govt refutes claims of CoWIN data breach; CERT-In reviews matter


PTI, Jun 12, 2023, 6:14 PM IST

Representative Image

The government on Monday said reports claiming a breach of data of beneficiaries registered on the CoWIN platform were ”mischievous” and ”without any basis”, and that the matter has been reviewed by the country’s nodal cyber security agency CERT-In.

The CoWIN portal is completely safe with adequate safeguards for data privacy, the Health Ministry said in a statement, adding an internal exercise has been initiated to review the existing security measures.

Rajeev Chandrasekhar, the Union Minister of State for Electronics and Information Technology, said the Indian Computer Emergency Response Team (CERT-In) immediately responded and it does not appear that Cowin app or database has been directly breached.

He said a Telegram Bot was throwing up Cowin app details upon entry of phone numbers. ”The data being accessed by bot from a threat actor database, which seems to have been populated with previously breached/stolen data stolen from past. It does not appear that Cowin app or database has been directly breached,” the minister said.

The health ministry said there are reports alleging the breach of data from the CoWIN portal, which is repository of all data of beneficiaries who have been vaccinated against COVID-19. ”It is clarified that all such reports are without any basis and mischievous in nature. Co-WIN portal of Health Ministry is completely safe with adequate safeguards for data privacy,” it said.

Furthermore, security measures are in place on CoWIN portal with web application firewall, regular vulnerability assessment, and Identity and Access Management, it said.

”Only OTP authentication-based access of data is provided. All steps have been taken and are being taken to ensure security of the data in the CoWIN portal,” the ministry said.

”CERT-In in its initial report has pointed out that backend database for Telegram bot was not directly accessing the APIs of CoWIN database,” the statement said.

It said certain Twitter users have claimed the personal data of individuals who have been vaccinated is being accessed using a Telegram (online messenger application) Bot.

It is reported that the bot has been able to pull individual data by simply passing the mobile number or Aadhaar number of a beneficiary, the ministry said.

The CoWIN was developed and is owned and managed by the Ministry of Health and Family Welfare. An Empowered Group on Vaccine Administration (EGVAC) was formed for steering the development of COWIN and for deciding on policy issues.

At present, the statement said, individual-level vaccinated beneficiary data access is available at three levels.

The first is the beneficiary dashboard — the person who has been vaccinated can have an access to the Co-WIN data through use of registered Mobile number with OTP authentication.

The second is CoWIN authorised user — the vaccinator with use of authentic login credential provided can access personal level data of vaccinated beneficiaries.

And, then there is API-based access — the third party applications who have been provided authorised access of Co-WIN APIs can access personal level data of vaccinated beneficiaries only through beneficiary OTP authentication.

The COWIN system tracks and keeps record of each time an authorided user accesses the COWIN system, the statement said.

”Without OTP, vaccinated beneficiaries’ data cannot be shared to any BOT,” the ministry said.

It further said only the year of birth is captured for adult vaccination but it seems that on media posts it has been claimed the Bot also mentioned the date of birth.

Also, there is no provision to capture the address of beneficiary, it said.

”The development team of COWIN has confirmed that there are no public APIs where data can be pulled without an OTP. In addition to the above, there are some APIs which have been shared with third parties such as ICMR for sharing data. It is reported that one such API has a feature of sharing the data by calling using just a mobile number of Aadhaar. However, even this API is very specific and the requests are only accepted from a trusted API which has been white-listed by the Co-WIN application,” it said.

Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.

Top News

No CM can remain absent for long, it’s against national interest: Delhi HC on Kejriwal

Politics behind sexual abuse charges against me and my son, claims MLA H D Revanna

Heatwave threat: Orange alert issued for 17 districts in Karnataka

PCB finalises Lahore, Karachi, Rawalpindi as venues for Champions Trophy

If voted to power, Congress will conduct caste, economic survey: Rahul Gandhi

‘Will PM still remain silent?’ Priyanka Gandhi slams BJP over Hassan ‘sex scandal’

IAF’s Resurgent Challenge in Pursuing Atmanirbharta

Related Articles More

ISRO releases ISSAR 2023 report on vulnerability of space assets to collisions

No CM can remain absent for long, it’s against national interest: Delhi HC on Kejriwal

Court convicts four accused, acquits 10 in 2015 Malvani hooch tragedy

ICG apprehends Indian fishing boat with 173 kg of narcotics; two crew members detained

Ahead of phase 3 polls, Congress and BJP spar in MP over quotas, Muslim appeasement

MUST WATCH

Skin Rash, Causes, Signs and Symptoms

11 bullets found in python’s body!

K. Jayaprakash Hegde Sharing His Memories

Grafting Jack Anil

Heat Illness


Latest Additions

ISRO releases ISSAR 2023 report on vulnerability of space assets to collisions

Hunasagi: MLA Bairati Basavaraj’s car overturned

No CM can remain absent for long, it’s against national interest: Delhi HC on Kejriwal

Cricket for the Blind: A Transformative Journey Empowering Visually Impaired Athletes

China lifts restrictions, gives all clear nod for Tesla cars as Musk lobbies hard in surprise visit to Beijing

Thanks for visiting Udayavani

You seem to have an Ad Blocker on.
To continue reading, please turn it off or whitelist Udayavani.