×
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT

Fact-Check: Was Indians' vaccine data on Co-Win actually leaked? Here's what experts believe

The allegedly fake data of 15 crore Indians was being sold for up to $800 on the dark web
Last Updated : 11 June 2021, 05:06 IST
Last Updated : 11 June 2021, 05:06 IST

Follow Us :

Comments

The government has refuted reports of user data being leaked from the CoWin portal and sold on the dark web, though it has launched an investigation into the issue out of caution.

Reports of an alleged hack of the vaccination site surfaced on Thursday, with pictures of a website on the dark web that claimed to be hawking the names, mobile numbers, Aadhaar IDs and location data of 15 crore vaccinated citizens.

"There have been some unfounded media reports on the CoWin platform being hacked. Prima facie, these reports appear to be fake," a statement issued by the Union health ministry said.

Union Health Minister Harsh Vardhan also rubbished the reports, saying that all vaccination data was stored in a “secure digital environment”, but said an emergency response team of the Ministry of Electronics and Information Technology would look into the matter just to be safe.

What do the experts believe?

Cybersecurity researcher Rajshekhar Rajaharia has backed the government’s assertion, saying the leak was completely fake and a Bitcoin scam that was set up to swindle unsuspecting buyers out of up to $800.

Rajaharia also posted pictures to prove that the website had regularly been posting fraudulent “leaked” datasets, including data from Tata Communications and SBI YONO, which were never hacked; Upstox and Mobikwik user data, which were not available on the dark web.

However, some cybersecurity experts are still concerned that the site’s security protocols were not impenetrable and suggested that the government err on the side of caution.

Apar Gupta, who runs the Internet Freedom Foundation (IFF), said the government should not take the claim lightly and implored the response team to investigate the breach thoroughly.

The IFF had earlier this year filed a Right to Information (RTI) petition regarding the kinds of data the Cowin portal stored and what its privacy policy was. The government said it would receive names, genders, dates of birth, photo IDs, and mobile numbers but refused to outline a privacy policy and did not disclose which ministries and departments in the government will have access to the data on the CoWin platform.

ADVERTISEMENT
Published 11 June 2021, 04:59 IST

Deccan Herald is on WhatsApp Channels| Join now for Breaking News & Editor's Picks

Follow us on :

Follow Us

ADVERTISEMENT
ADVERTISEMENT