Govt denies CoWin data breach

NEW DELHI, June 12:

The Government today said reports claiming a breach of data of beneficiaries registered on the CoWin platform were “mischievous” and “without any basis”, and that the matter has been reviewed by the country’s nodal cyber security agency CERT-In.
The CoWin portal is completely safe with adequate safeguards for data privacy, the Health Ministry said in a statement, adding an internal exercise has been initiated to review the existing security measures.
Rajeev Chandrasekhar, the Union Minister of State for Electronics and Information Technology, said the Indian Computer Emergency Response Team (CERT-In) immediately responded and it does not appear that CoWin app or database has been directly breached.
He said a Telegram Bot was throwing up CoWin app details upon entry of phone numbers. “The data being accessed by bot from a threat actor database, which seems to have been populated with previously breached/ stolen data stolen from past. It does not appear that CoWin app or database has been directly breached,” the minister said.
The health ministry said there are reports alleging the breach of data from the CoWin portal, which is repository of all data of beneficiaries who have been vaccinated against COVID-19.
“It is clarified that all such reports are without any basis and mischievous in nature. CoWin portal of Health Ministry is completely safe with adequate safeguards for data privacy,” it said.
Furthermore, security measures are in place on CoWIN portal with web application firewall, regular vulnerability assessment, and Identity and Access Management, it said.
“Only OTP authentication-based access of data is provided. All steps have been taken and are being taken to ensure security of the data in the CoWIN portal,” the Ministry said. (PTI)