Indian government’s cloud spilled citizens’ personal data online for years

Date:

Share post:


The Indian government has finally resolved a years-long cybersecurity issue that exposed reams of sensitive data about its citizens. A security researcher exclusively told TechCrunch he found at least hundreds of documents containing citizens’ personal information — including Aadhaar numbers, COVID-19 vaccination data, and passport details — spilling online for anyone to access.

At fault was the Indian government’s cloud service, dubbed S3WaaS, which is billed as a “secure and scalable” system for building and hosting Indian government websites.

Security researcher Sourajeet Majumder told TechCrunch that he found a misconfiguration in 2022 that was exposing citizens’ personal information stored on S3WaaS to the open internet. Because the private documents were inadvertently made public, search engines also indexed the documents, allowing anyone to actively search the internet for the sensitive private citizen data.

With support from digital rights organization the Internet Freedom Foundation, Majumder reported the incident at the time to India’s computer emergency response team, known as CERT-In, and the Indian government’s National Informatics Centre.

CERT-In quickly acknowledged the issue, and links containing sensitive files from public search engines were pulled down.

But Majumder said that despite repeated warnings about the data spill, the Indian government cloud service was still exposing some individuals’ personal information as recently as last week.

With evidence of ongoing exposures of private data, Majumder asked TechCrunch for help getting the remaining data secured. Majumder said that some citizens’ sensitive data began spilling online long after he first disclosed the misconfiguration in 2022.

TechCrunch reported some of the exposed data to CERT-In. Majumder confirmed that those files are no longer publicly accessible.

When reached prior to publication, CERT-In did not object to TechCrunch publishing details of the security lapse. Representatives for the National Informatics Centre and S3WaaS did not respond to a request for comment.

Majumder said it was not possible to accurately estimate the true extent of this data leak, but warned that bad actors were purportedly selling the data on a known cybercrime forum before it was shuttered by U.S. authorities. CERT-In would not say if bad actors accessed the exposed data.

The exposed data, Majumder said, potentially puts citizens at risk of identity thefts and scams.

“More than that, when sensitive health information like COVID test results and vaccine records get out, it’s not just our medical privacy that’s compromised — it stirs fears of discrimination and social rejection,” he said.

Majumder noted that this incident should be a “wake-up call for security reforms.”



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

Investors are feverishly continuing to evaluate AI startups, and to try to avoid simply chasing a fad,...

Blackboard founder transforms Zoom add-on designed for teachers into business tool

When Class founder Michael Chasen was in college, he and a buddy came up with the idea...

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Hydrow, the at-home rowing machine, announced Thursday that it has acquired a majority stake in Speede Fitness,...

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced...

India weighs delaying caps on UPI market share in win for PhonePe, Google Pay

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the...

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on...

Apple’s ‘Crush’ ad is disgusting

Apple can generally be relied on for clever, well-produced ads, but it missed the mark with its...

OpenAI offers a peek behind the curtain of its AI’s secret instructions

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite...