Research firm discloses exposure of 73 lakh BHIM app users’ data
Category: #tech  By Mateen Dalal  Date: 2020-06-03
  • share
  • Twitter
  • Facebook
  • LinkedIn

Research firm discloses exposure of 73 lakh BHIM app users’ data

An independent cyber-security research firm has reportedly revealed that the private details of around 73 lakh Indians in the BHIM app are being exposed. The firm allegedly claimed that users are likely to encounter data-based fraud due to the lax security standards supported in this UPI app.

Sources familiar with the matter have reported that CSC e-Governance Services has left a cloud data storage bucket of its Amazon Web Services S3 unsecured and thus open to the public. This data storage misconfiguration happened during February 2019 and May 2020, the month when it has been repaired. The level of security lapse and its impact is still not clear since the privacy of numerous users has been left exposed for nearly a year.

Sources further stated that the PAN details, banking & financial transcripts, educational degrees, residential address proofs, caste certificates, and Aadhaar cards are among the data that can be accessed via the AWS S3 bucket. Due to the recent security bug, the residential address, biometric authentication info, and other information of the 73 lakh users were revealed online.

However, the NPCI (National Payments Council of India) has reportedly denied the occurrence of any data breach of the UPI users. Sources further clarified that there was no data being compromised at the BHIM app. According to statements, NPCI follows an integrated approach and high-level security to safeguard the infrastructure and continuously offer a strong payments ecosystem.

The unsecured data bucket was reportedly 409 GB in size, which was discovered by the agency on 13th April. Following this glitch, the firm reported it to the CERT-In (Computer Emergency Response Team) in India on 28th April. The unsecured bucket was patched soon after it contacted the CERT-In again on 22nd May.

Provided that this data bucket was opened to risks for over a year, it is unclear whether malicious users have managed to get hold of such data. This lapse in the security standard will create alarm, despite the denial of the incident from the NPCI, regarding security among other digital initiatives backed by the government.

Source credit:https://www.news18.com/news/tech/private-details-of-73-lakh-indians-exposed-in-bhim-data-leak-npci-issues-denial-2648189.html

  • share
  • Twitter
  • Facebook
  • LinkedIn


About Author

Mateen Dalal    

Mateen Dalal

A qualified electronics and telecommunication engineer, Mateen Dalal embarked on his professional journey working as a quality and test engineer. Harnessing his passion for content creation however, Mateen pens down industry-rich articles for ReportsGO.com and a few o...

Read More

More News By Mateen Dalal

AstraZeneca to present results of Farxiga’s DAPA-CKD trial at ESC 2020
AstraZeneca to present results of Farxiga’s DAPA-CKD trial at ESC 2020
By Mateen Dalal

According to reliable sources, British-Swedish multinational pharmaceutical company AstraZeneca plc will present the much awaited results of the Phase III DAPA-CKD trial of Farxiga in CKD (chronic kidney disease) at ESC Congress 2020. Sources with r...

FDA grants Emergency Use Authorization to Abbott’s COVID-19 antigen
FDA grants Emergency Use Authorization to Abbott’s COVID-19 antigen
By Mateen Dalal

Abbott Laboratories, a U.S.-based medical devices and healthcare firm, has reportedly received the Emergency Use Authorization (EUA) from the U.S. FDA (Food and Drug Administration) for the detecting COVID-19 virus with its portable antigen test Bina...

Hyundai Wia Corp. signs gun parts export contract with BAE Systems
Hyundai Wia Corp. signs gun parts export contract with BAE Systems
By Mateen Dalal

Hyundai Wia Corp., a South Korea-based defense firm, has reportedly signed gun parts export contract with BAE Systems plc of worth USD 100 million via a pre-value accumulation system. As per the agreement, Hyundai Wia will supply over 106 types of gu...