Search module is not installed.

No data leaked from Co-WIN portal, says NHA

21.01.2022

The National Health Authority NHA denies any Covid-related data leak from the Co-WIN portal on the prima facie basis, saying the platform neither collects the address of people nor RT-PCR test results for vaccination, a top official said on Friday.

The cyber criminals posted personal data of thousands of people on the dark web, claiming they were from India.

The assertion is not correct, and we will enquire into the substance of the news. Co-WIN does not collect the address of the person or the RT-PCR test results for vaccination. The National Health Authority Sharma said that no data has been leaked from the Co-WIN portal and that the entire data of residents is safe and secure on our platform.

The alleged leak of data was put on the Raid Forums website, where a cyber criminal claims to have personal data of over 20,000 people.

Cyber Security researcher Rajshekhar Rajaharia said that Google indexed lakhs of data from the affected system, including name and Covid 19 results, is made public through a content delivery network CDN.

The PII including Name, MOB, PAN, Address, etc. of Covid 19 RTPCR results Cowin data getting public through a Govt CDN. Google indexed 9 Lac public GovtDocuments in search engines. Patient's data is now listed on DarkWeb. In his tweet, Rajaharia said that he needed to do a quick deindex.

The government has relied heavily on digital technologies in order to control and create awareness about the Covid-19 pandemic, as well as its vaccination programme. There are several government departments that require people to use the Aarogya Setu app for Covid 19 related services and information.

In a follow-up tweet on January 20, Rajaharia said he is not reporting any vulnerability in this incident but he warns people to stay alert from fraud calls, offers related to Covid- 19, etc. that they may get as their data is being sold in the dark web.

Cyber criminals and fraudsters are known to exploit the data in the dark web for various types of fraud.