The Indian authorities has lastly resolved a years-long cybersecurity concern that uncovered reams of delicate data about its residents. A safety researcher completely informed TechCrunch he discovered at the very least lots of of paperwork containing residents’ personal info — together with Aadhaar numbers, COVID-19 vaccination data, and passport particulars — spilling online for anybody to entry.
At fault was the Indian authorities’s cloud service, dubbed S3WaaS, which is billed as a “safe and scalable” system for constructing and internet hosting Indian authorities web sites.
Security researcher Sourajeet Majumder informed TechCrunch that he discovered a misconfiguration in 2022 that was exposing residents’ personal info saved on S3WaaS to the open web. Because the non-public paperwork had been inadvertently made public, search engines like google additionally listed the paperwork, permitting anybody to actively search the web for the delicate non-public citizen data.
With help from digital rights group the Internet Freedom Foundation, Majumder reported the incident on the time to India’s pc emergency response staff, often called CERT-In, and the Indian authorities’s National Informatics Centre.
CERT-In rapidly acknowledged the difficulty, and hyperlinks containing delicate information from public search engines like google had been pulled down.
But Majumder mentioned that regardless of repeated warnings concerning the data spill, the Indian authorities cloud service was nonetheless exposing some people’ personal info as lately as final week.
With proof of ongoing exposures of personal data, Majumder requested TechCrunch for assist getting the remaining data secured. Majumder mentioned that some residents’ delicate data started spilling online lengthy after he first disclosed the misconfiguration in 2022.
TechCrunch reported a few of the uncovered data to CERT-In. Majumder confirmed that these information are now not publicly accessible.
When reached previous to publication, CERT-In didn’t object to TechCrunch publishing particulars of the safety lapse. Representatives for the National Informatics Centre and S3WaaS didn’t reply to a request for remark.
Majumder mentioned it was not potential to precisely estimate the true extent of this data leak, however warned that dangerous actors had been purportedly promoting the data on a identified cybercrime discussion board earlier than it was shuttered by U.S. authorities. CERT-In wouldn’t say if dangerous actors accessed the uncovered data.
The uncovered data, Majumder mentioned, probably places residents susceptible to id thefts and scams.
“More than that, when delicate well being info like COVID take a look at outcomes and vaccine data get out, it’s not simply our medical privateness that’s compromised — it stirs fears of discrimination and social rejection,” he mentioned.
Majumder famous that this incident ought to be a “wake-up name for safety reforms.”



