Data Breach on CSC BHIM Site Puts 70 Lakhs Indians' Highly Sensitive Data at Risk: Report

The vulnerability on CSC BHIM site was first detected on April 23 and it is said that the loophole was fixed on May 22.

Advertisement
By Abhik Sengupta | Updated: 1 June 2020 17:46 IST
Highlights
  • Sensitive data was reportedly found in an unsecured server
  • Exposed data includes Aadhaar card details, PAN number and more
  • Government is yet to publicly address this issue

409GB worth of data was lying unsecured on cloud storage.

Aadhaar cards, caste certificates, and other highly sensitive personal data of over 70 lakh Indians have reportedly been exposed by a government website. The CSC BHIM website, used to promote UPI payments app BHIM, reportedly suffered a massive data breach. The CSC e-Governance Service India is a program to bring digital access to villages, and the CSC BHIM project was launched to get merchants at the village level to start accepting UPI payments through QR codes. Apparently, a tremendous amount of data of Indian citizens was gathered on the site, and this information has now been breached.

According to Israeli cybersecurity company vpnMentor, 409GB of data of users in India have been exposed, which includes a huge amount of highly sensitive, personally identifiable information. The company said that the exposure of this user data is akin to a hacker gaining "access to the entire data infrastructure of a bank," along with users' account information. The vulnerability was detected first on April 23 and it is said that the loophole was fixed on May 22.

Based on the report so far, there is no evidence yet that the BHIM app itself was leaking data, or that the UPI system is insecure.

Advertisement

How was CSC BHIM data breached?

The report by vpnMentor claims that the data collected for BHIM deployment was being stored on a misconfigured Amazon Web Services S3 bucket and was "publicly accessible." This has been found to be a fairly common error that many websites make when setting up their cloud systems. As per vpnMentor, 409GB worth of sensitive data of individuals and several merchants were lying unsecured, therefore, exposing them to potential fraud, theft, and attack from hackers and cybercriminals.

Advertisement

Sensitive data of lakhs of Indians was stored in cloud storage without security protocols on the account to ensure safety.

"...the data was stored on an unsecured Amazon Web Services (AWS) S3 bucket. S3 buckets are a popular form of cloud storage across the world but require developers to set up the security protocols on their accounts. The exposed S3 bucket was labelled 'csc-bhim,' and our team was quickly able to identify the developers behind the website 'www.cscbhim.in' as the owners of the data," claim Noam Rotem and Ran Locar, cybersecurity researchers at vpnMentor.

Advertisement

What all data was compromised in the CSC BHIM breach?

According to vpnMentor, the following were some of the personal documents that were found in the exposed S3 bucket:

  • Scans of Aadhaar cards – India's national ID
  • Scans of Caste certificates
  • Photos used as proof of residence
  • Professional certificates, degrees, and diplomas
  • Screenshots taken within financial and banking apps as proof of fund transfers
  • Permanent Account Number (PAN) cards (associated with Indian income tax services)

Aside from this, the leak also included UPI VPAs (transaction IDs) of people.

Advertisement

Impact of the CSC BHIM data breach

The cybersecurity company said that the data breach exposes highly sensitive data including individual's Aadhaar card information, caste certificates, proof of residence, professional certificates and degrees, and scans of Permanent Account Number (PAN) cards.

"Based on our research, the S3 bucket also contained documents and PII [Personally identifiable information] data for minors," company said. The cybersecurity company explains that having such sensitive financial data in the public domain would make it "incredibly easy to trick, defraud, and steal from the people exposed."

"The exposure of private data may also contribute to a broader deterioration of trust between the Indian public, government bodies, and technology companies," the company added.

What has the government said over the CSC BHIM data vulnerability?

The report states that the cybersecurity company reached out to the developers of CSC BHIM site to inform about the breach, however, no contact was established. The company then reached out India's Computer Emergency Response Team (CERT-In), which deals with cybersecurity in the country on April 28 and the problem was reportedly rectified on May 22, without further response.

Gadgets 360 has also reached out to the National Payments Corporation of India, and Computer Emergency Response Team for more clarity.


Is Realme TV the best TV under Rs. 15,000 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Neo 11 With Snapdragon 8 Elite SoC Launched: Price, Specifications
  2. Vivo X300 Series With 200-Megapixel Zeiss Camera Launched Globally
  3. iQOO 15 Indian Variant Allegedly Surfaces on Geekbench Ahead of Launch
  4. WhatsApp Will Soon Let You Reply, React to Messages Using Your Apple Watch
  5. OpenAI's Sora App Will Now Charge You for Extra AI Video Generations
  6. You Can Now Repair the iPhone 17 Series, iPhone Air Yourself in These Regions
  7. Samsung Will Build an AI Megafactory in Partnership With Nvidia
  8. Lava Agni 4 With Metal Design and Flat Edges Teased Ahead of Debut
  9. Realme GT 8 Pro India Launch Date Leaked: Here's When It Might Arrive
  10. Gemini vs Perplexity vs ChatGPT: Which Free AI Plan Is Best For You
  1. Bitcoin Slips to $109,000 as Traders React to Uncertainty Over Future US Fed Rate Cuts
  2. OnePlus 15T Launch Timeline, Key Features Leaked Again; Could Feature a 7,000mAh Battery
  3. Realme GT 8 Pro Teased to Come With 2K Display and Ultra Haptics Motor Ahead of India Launch
  4. Samsung and Nvidia Partner to Build an AI Megafactory to Automate Manufacturing
  5. Honor GT 2 Series Specifications, Launch Timeline Leaked; Could Feature Flagship Snapdragon Chips
  6. Samsung Galaxy Book 6 Pro Allegedly Listed on Geekbench With Intel Core Ultra 5 SoC, 32GB of RAM
  7. OpenAI Tells Users to Pay for Extra AI Video Generations on the Sora App
  8. Google Pixel 10 Pro, Galaxy Z Fold 7 Offer Better Scam, Fraud Protection Than iPhone 17 Pro: Study
  9. WhatsApp Tests Companion App for Apple Watch With Core Messaging Functionality
  10. Samsung Internet Browser Beta for Windows PCs Launched with Galaxy AI Integration
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.