COVID-19 Surveillance Tool Apparently Used in Uttar Pradesh Exposed Data of Over 80 Lakh People: Researchers

Researchers noticed the data breach through the tool called “Surveillance Platform Uttar Pradesh COVID-19” initially on August 1.

Advertisement
By Jagmeet Singh | Updated: 22 September 2020 17:36 IST
Highlights
  • Initial vulnerability was found an unsecured git repository
  • The tool exposed names, numbers, and addresses of individuals
  • It included data of non-Indian citizens and foreign residents as well

The COVID-19 surveillance tool was discovered exposing personalising identifiable data of individuals

A COVID-19 surveillance tool that was apparently built by the state government of Uttar Pradesh put the data of 80 lakh citizens at risk, according to a report. The tool was found to have numerous vulnerabilities that all were exposing personally identifiable information data that included full names, ages, genders, resident addresses, and phone numbers of every individual who was tested for COVID-19 in the country's biggest state and its other parts, according to researchers. The data breach got secured on September 10 — over a month after it was first noticed.

Researchers from virtual private network (VPN) service provider VPNMentor noticed the data breach through the tool called “Surveillance Platform Uttar Pradesh COVID-19” on August 1. The surveillance platform was compromised through various vulnerabilities and all of them were pointing to a severe lack of security, the researchers noted in a blog post.

The first vulnerability was found in an unsecured git repository that contained a “data dump” of stored login credentials including usernames and passwords for admin accounts on the platform. Based on the initial discovery, VPNMentor analysts Noam Rotem and Ran Locar discovered an exposed Web index that contained a directory listing of CSV files. Those files listed all known cases of COVID-19 testing in Uttar Pradesh and other parts of India, reaching the amount of over 80 lakh people. There were data such as full names, addresses, and phone numbers along with test results of individuals.

Advertisement

The Web index also included the data of non-Indian citizens and foreign residents. Further, there were lists that had the information about many healthcare workers, according to the discovery.

Advertisement

Researchers mentioned in the blog post that the Web index was accessible without any password and was completely open to the public.

“While the directory listing didn't directly impact Uttar Pradesh's surveillance platform, it severely compromised the safety of the millions of people listed in the CSV files, whose data probably originated from the surveillance platform and other sources,” the researchers said.

Advertisement

After collecting the details from the discovery, the researchers submitted the report to share with the Indian government. The report was forwarded to the country's Computer Emergency Response Team CERT-In on August 27. The team of researchers also reached the UP cybercrime department, though it didn't respond. On September 7, CERT-In was reached out again by the researchers that eventually helped fix the issues, as per the blog post.

“Such malicious actions would have many real-world consequences on the effectiveness of Uttar Pradesh's response and action against coronavirus, potentially causing extreme disruption and chaos,” the researchers noted.

Advertisement

There is no information whether any of the exposed data was compromised by an attacker. However, the researchers at VPNMentor believe that the effect of the vulnerabilities in the surveillance tool could be felt far beyond the authorities working on COVID-19 relief in Uttar Pradesh.


Should the government explain why Chinese apps were banned? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: COVID 19, coronavirus, Uttar Pradesh
Advertisement

Related Stories

Popular Mobile Brands
  1. Moto G67 Power 5G Launched in India With 7,000mAh Battery: See Price
  2. Samsung Galaxy S26 Ultra Spotted in Leaked Renders With Rounder Corners
  3. Silicon-Carbide Motor Drive Revolutionizes Hybrid Flight
  4. OnePlus Ace 6 Pro Max Configurations Leaked; May Feature Up to 16GB of RAM
  5. WhatsApp's Apple Watch App Is Finally Out: Check Features, Compatibility
  6. Apple's Low-Cost MacBook Launch Timeline, Price Leaked Ahead of Debut
  7. Moto G Play (2026), Moto G (2026) With Dimensity 6300 SoC Launched
  8. Moto G67 Power 5G Launch Today: Everything You Need to Know
  9. Southern Taurid Meteor Shower 2025 Promises Bright Fireballs in a Rare Swarm Year
  1. Scientists Recreate Cosmic ‘Fireballs’ in Lab to Solve Mystery of Missing Gamma Rays
  2. Realme UI 7.0 Launched With Light Glass Design, AI Notify Brief and AI Gaming Coach: See Eligible Phones, Beta Release Schedule
  3. iOS 26.2 Beta 1 Rolled Out to Developers With Enhanced Safety Alerts, Reminder Alarms
  4. Samsung Galaxy S26 Ultra Spotted in Leaked Design Renders That Hint at Rounder Corners
  5. Call of Duty: Black Ops 7 PC Specifications, Preloading Times Revealed; Activision Confirms Handheld Support
  6. Silicon Carbide-Based Motor Drive Enables a Smaller, Lighter Electric Aircraft Engine
  7. OnePlus Ace 6 Pro Max Key Features Leaked; May Be Equipped With Up to 16GB of RAM
  8. Moto G67 Power 5G Launched in India With 7,000mAh Battery, 50-Megapixel Sony Camera: Price, Specifications
  9. Southern Taurid Meteor Shower 2025 Promises Bright Fireballs in a Rare Swarm Year
  10. Moto G Play (2026), Moto G (2026) With MediaTek Dimensity 6300 SoC Launched: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.