A tool tracking the spread of COVID-19, built by the Uttar Pradesh, exposed personal data of about 8 million Indian citizens.

VPNmentor conducted an investigation into the COVID-19 tracking tool in question, called the Uttar Pradesh COVID-19 Surveillance Platform , and discovered that it was breached on August 1, leading to a data leak .
As the researchers discovered, there were several vulnerabilities that could have compromised the virus tracking platform . However, what ultimately led to the breach was the lack of security measures
VPNmentor researchers noted that the Uttar Pradesh state government developed the tool as part of a large-scale mapping project. Its primary purpose was to identify and track coronavirus patients across India, and the lack of “data security protocols left access to the platform open,” exposing the data of millions in India.
Researchers claim that the COVID-19 tracing tool contained multiple vulnerabilities that exposed users' personal data. The exposed data includes full names, gender, age, home address, and contact numbers of all people who had tried the tool.
The data was secured a month after the breach was discovered. According to VPNMentor analysts Ran Locar and Noam Rotem, the first vulnerability was found in an unsecured and unencrypted git repository, which included usernames, admin accounts, and passwords stored on the platform.
Based on this discovery, the researchers found an exposed Web Index, which contained a list of CSV file directories. It contained information on all known COVID-19 cases in UP and other locations in India.
Sensitive private data, including full names, phone numbers, addresses and test results of about 8 million citizens, was part of the list. The list also contained information about foreign residents and healthcare workers and was not password-protected.
There is no evidence that any malicious actor used the exposed data for fraud, but researchers believe the impact of the vulnerabilities in the tracking tool could be widespread.
