HomeSecurityCOVID-19 tracking tool exposes data of millions of users

COVID-19 tracking tool exposes data of millions of users

A tool tracking the spread of COVID-19, built by the Uttar Pradesh, exposed personal data of about 8 million Indian citizens.

Covid-19

VPNmentor conducted an investigation into the COVID-19 tracking tool in question, called the Uttar Pradesh COVID-19 Surveillance Platform , and discovered that it was breached on August 1, leading to a data leak .

As the researchers discovered, there were several vulnerabilities that could have compromised the virus tracking platform . However, what ultimately led to the breach was the lack of security measures

VPNmentor researchers noted that the Uttar Pradesh state government developed the tool as part of a large-scale mapping project. Its primary purpose was to identify and track coronavirus patients across India, and the lack of “data security protocols left access to the platform open,” exposing the data of millions in India.

Researchers claim that the COVID-19 tracing tool contained multiple vulnerabilities that exposed users' personal data. The exposed data includes full names, gender, age, home address, and contact numbers of all people who had tried the tool.

The data was secured a month after the breach was discovered. According to VPNMentor analysts Ran Locar and Noam Rotem, the first vulnerability was found in an unsecured and unencrypted git repository, which included usernames, admin accounts, and passwords stored on the platform.

Based on this discovery, the researchers found an exposed Web Index, which contained a list of CSV file directories. It contained information on all known COVID-19 cases in UP and other locations in India.

Sensitive private data, including full names, phone numbers, addresses and test results of about 8 million citizens, was part of the list. The list also contained information about foreign residents and healthcare workers and was not password-protected.

There is no evidence that any malicious actor used the exposed data for fraud, but researchers believe the impact of the vulnerabilities in the tracking tool could be widespread.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS