A man from the state of Bihar has been arrested by the Delhi Police Special Cell’s IFSO (Intelligence Fusion and Strategic Operations) Unit in connection with the alleged data leak at CoWIN portal. ANI, a media group, reported that the Bihar man uploaded the breached data on a messaging platform. According to the sources the data of the CoWIN has been uploaded on the Telegram platform. The accused’s mother reportedly works as a health care worker in Bihar.
A juvenile has also been arrested in the alleged data leak case.
In the past week, there have been several reports about a data leak at the CoWIN platform. CoWIN is a platform that provides information about vaccinated individuals.
This incident is not the first, although last week also a report surfaced related to data leak of the beneficiaries registered on the CoWIN platform. Those data has been accessed using Telegram bot, can be used to access users’ data by entering an eligible number or Aadhaar details. The user can then gain access to the user’s data such as gender, dates of birth, Aadhaar details, address, vaccination centre information, etc
Government officials reply to this CoWIN data leak
The government has launched an investigation into the incident. The Health Ministry has reassured the public that CoWIN website has strong data privacy safeguards in place.
The Ministry of Health has denied reports that data can be accessed from Telegram bots without mobile numbers or Aadhaar numbers.
In a tweet, the minister for electronics and information technology, Rajeev Chandrashekhar said that the data accessed by the bot appears to have been stolen from databases outside CoWIN.
The Telegram bot is not using the application programming interface (API) of CoWIN, according to a press release issued on June 12 by the Union Ministry of health and family welfare (MoHFS).According to a statement released by the Ministry of Electronics and information technology (MEIT) on June 12, CERT-In (Nodal Cyber Security Agency), which is part of the Indian government, the alleged breach was not “directly” breached. CERT-In is the Indian government’s cyber security agency. According to the statement released by the MoHFS, the Telegram bot is using “previously compromised databases.
About CoWIN
Co-WIN is an end-to-end solution that provides utilities for the whole public health system from the national level to the vaccinators level. The system enables the creation of users (Admin, Supervisor, Vaccinator), registration of recipients (Bulk upload and Individual Registration), facilities/Planning Unit and session sites, planning and scheduling of sessions and implementation of the vaccination process. The Co-WIN system will track not only beneficiaries but also vaccines at the national, state and sub-district level. This will enable the system to track utilization, wastage and coverage of the COVID-19 vaccine at the national level, state level, district level, etc.