A joke doing the rounds says that according to Modi government, everything from Defence Ministry website to the most sophisticated computer can be hacked, but not EVMs or Aadhaar data.
That in fact sums up the response of the government and the joke has frequently been on the people with repeated reports of Aadhaar data breach.
This time, confidential data on subscribers of the Employees’ Provident Fund Organisation (EPFO) was found to have been stolen by hackers. The EPFO had to shut down the portal that was used to seed Aadhaar details with PF accounts.
The matter came to light when a letter from EPFO Central Provident Fund Commissioner VP Joy surfaced on Twitter.
According to a letter, which Joy wrote to Dinesh Tyagi, CEO of Common Service Centre (CSC) which managed the EPFO website with the data, Intelligence Bureau (IB) had informed the labour ministry in March about the data theft from the aadhaar.epfoservices.com website that helps link the Aadhaar numbers of subscribers with their EPF account numbers.
The website had subscribers data related to their Aadhaar number, Permanent Account Number or PAN, personal family and salary details.
“It has been intimated that the data has been stolen by hackers by exploiting the vulnerabilities prevailing in the website (aadhaar.epfoservices.com) of EPFO,” Joy wrote in the letter to Tyagi, according to LiveMint.
The letter said that the IB has advised adhering to “best practices and guidelines for securing the confidential data, re-emphasising regular and meaningful audit and vulnerability assessment and penetration testing of the entire system from competent auditors and testers stated.”
“The web portal has been closed one-and-a-half months ago, immediately after a possible data theft was reported to us during a process of routine security check,” Joy told Business Standard Wednesday, May 2.
“There was some problem in the application run by CSC and it is not related to our data centre that maintains the EPF accounts.”
After the scare over the reported breach, the EPFO on Wednesday, May 3 said in a statement, “No confirmed data leakage has been established or observed so far. As part of the data security and protection, EPFO has taken advance action by closing the server and host service through Common Service Centres pending vulnerability checks.”
However, Joy was reported as saying in an interview, “I don’t know how my letter got leaked. We shall find out,” according to LiveMint. He said EPFO has “taken care of the vulnerabilities and soon after it was warned about the vulnerability of data it stopped availing services of the CSC.”
The UIDAI also said that the breach wasn’t from its server.
However, the government sources have now confirmed that details of PF accounts were compromised for “a few weeks,” before it was detected and the portal was taken down, reported the Huff Post.