Data Breach on CSC BHIM Site Puts 70 Lakhs Indians' Highly Sensitive Data at Risk: Report

The vulnerability on CSC BHIM site was first detected on April 23 and it is said that the loophole was fixed on May 22.

Advertisement
By Abhik Sengupta | Updated: 1 June 2020 17:46 IST
Highlights
  • Sensitive data was reportedly found in an unsecured server
  • Exposed data includes Aadhaar card details, PAN number and more
  • Government is yet to publicly address this issue

409GB worth of data was lying unsecured on cloud storage.

Aadhaar cards, caste certificates, and other highly sensitive personal data of over 70 lakh Indians have reportedly been exposed by a government website. The CSC BHIM website, used to promote UPI payments app BHIM, reportedly suffered a massive data breach. The CSC e-Governance Service India is a program to bring digital access to villages, and the CSC BHIM project was launched to get merchants at the village level to start accepting UPI payments through QR codes. Apparently, a tremendous amount of data of Indian citizens was gathered on the site, and this information has now been breached.

According to Israeli cybersecurity company vpnMentor, 409GB of data of users in India have been exposed, which includes a huge amount of highly sensitive, personally identifiable information. The company said that the exposure of this user data is akin to a hacker gaining "access to the entire data infrastructure of a bank," along with users' account information. The vulnerability was detected first on April 23 and it is said that the loophole was fixed on May 22.

Based on the report so far, there is no evidence yet that the BHIM app itself was leaking data, or that the UPI system is insecure.

Advertisement

How was CSC BHIM data breached?

The report by vpnMentor claims that the data collected for BHIM deployment was being stored on a misconfigured Amazon Web Services S3 bucket and was "publicly accessible." This has been found to be a fairly common error that many websites make when setting up their cloud systems. As per vpnMentor, 409GB worth of sensitive data of individuals and several merchants were lying unsecured, therefore, exposing them to potential fraud, theft, and attack from hackers and cybercriminals.

Advertisement

Sensitive data of lakhs of Indians was stored in cloud storage without security protocols on the account to ensure safety.

"...the data was stored on an unsecured Amazon Web Services (AWS) S3 bucket. S3 buckets are a popular form of cloud storage across the world but require developers to set up the security protocols on their accounts. The exposed S3 bucket was labelled 'csc-bhim,' and our team was quickly able to identify the developers behind the website 'www.cscbhim.in' as the owners of the data," claim Noam Rotem and Ran Locar, cybersecurity researchers at vpnMentor.

Advertisement

What all data was compromised in the CSC BHIM breach?

According to vpnMentor, the following were some of the personal documents that were found in the exposed S3 bucket:

  • Scans of Aadhaar cards – India's national ID
  • Scans of Caste certificates
  • Photos used as proof of residence
  • Professional certificates, degrees, and diplomas
  • Screenshots taken within financial and banking apps as proof of fund transfers
  • Permanent Account Number (PAN) cards (associated with Indian income tax services)

Aside from this, the leak also included UPI VPAs (transaction IDs) of people.

Advertisement

Impact of the CSC BHIM data breach

The cybersecurity company said that the data breach exposes highly sensitive data including individual's Aadhaar card information, caste certificates, proof of residence, professional certificates and degrees, and scans of Permanent Account Number (PAN) cards.

"Based on our research, the S3 bucket also contained documents and PII [Personally identifiable information] data for minors," company said. The cybersecurity company explains that having such sensitive financial data in the public domain would make it "incredibly easy to trick, defraud, and steal from the people exposed."

"The exposure of private data may also contribute to a broader deterioration of trust between the Indian public, government bodies, and technology companies," the company added.

What has the government said over the CSC BHIM data vulnerability?

The report states that the cybersecurity company reached out to the developers of CSC BHIM site to inform about the breach, however, no contact was established. The company then reached out India's Computer Emergency Response Team (CERT-In), which deals with cybersecurity in the country on April 28 and the problem was reportedly rectified on May 22, without further response.

Gadgets 360 has also reached out to the National Payments Corporation of India, and Computer Emergency Response Team for more clarity.


Is Realme TV the best TV under Rs. 15,000 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R, OnePlus 15R Ace Edition Launch Today: All You Need to Know
  2. Filmfare OTT Awards 2025: Check out Full List of Winners
  3. Realme Narzo 90 Series With 7,000mAh Battery Launched in India: See Pricing
  4. Xiaomi's HyperOS 3 Update Is Rolling Out to These Phones, Tablets
  5. OpenAI Says ChatGPT Will Soon Become an Operating System
  6. Oppo Find X9 Ultra Battery Capacity Teased By Company Executive
  7. Astronomers Witness Longest-Lasting Gamma-Ray Burst in History, 8 Billion Light-Years Away
  8. Disney Is Keeping Its Options Open For Future AI Partnerships
  9. Realme 16 Pro to Launch With Urban Wild Design in These Four Colourways
  10. Nothing Phone 3a Lite Review: The Best Mid-Range Design
  1. OnePlus 15R, OnePlus 15R Ace Edition Launching Today: Know Price in India, Features, Specs and More
  2. Astronomers Witness Longest-Lasting Gamma-Ray Burst in History, 8 Billion Light-Years Away
  3. Sub-Millimeter Robots Can Sense, Think, and Act Autonomously, New Study Finds
  4. Earth’s Atmosphere Has Been Leaking Onto the Moon for Billions of Years, Study Finds
  5. New Orbital Clues Reveal How Hot Jupiters Moved Close to Their Stars
  6. Heartiley Battery Out on OTT: Know Where to Watch This Tamil Sci-Fi Series Online
  7. Raat Akeli Hai: The Bansal Murders OTT Release Date: When and Where to Watch it Online?
  8. Private Satellites Pinpoint Methane Emissions from Oil, Gas, and Coal Facilities Worldwide
  9. Ishq Vishk Rebound Out on OTT: Know Where to Watch This Rohit Saraf Starrer Romcom
  10. Theeyavar Kulai Nadunga Now Streaming Online: Where to Watch This Dark Psychology Thriller
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.