CoWIN Data Breach: Government Responds, Says no Direct Breach of CoWIN App or Database

According to the government, CoWIN data access is available at three levels — the vaccine recipient, an authorised vaccinator, and third-party apps.

Advertisement
Written by David Delima, Edited by Siddharth Suvarna | Updated: 12 June 2023 18:53 IST
Highlights
  • The government has denied any breach of CoWIN databases
  • CoWIN data can be accessed at three levels, as per the government
  • CERT-In shared its findings after the alleged data breach surfaced online

The government has clarified there are no public APIs offering access to data without an OTP

Photo Credit: Reuters

The government on Monday responded to reports of an alleged data breach of the CoWIN database, stating that the data appeared to have been sourced from a different database containing information stolen in the past. The response follows reports that an automated bot on Telegram was surfacing personal details of people who had registered with the CoWIN platform to receive COVID vaccinations during the pandemic. The government has also claimed that it did not appear that the CoWIN app or database had been directly breached.

Hours after reports of the alleged data breach, Minister of State for Electronics and Technology Rajeev Chandrasekhar stated on Twitter that the Indian Computer Emergency Response Team (CERT-In) had responded and reviewed the reports of breaches that surfaced on social media on Monday. The minister stated a Telegram bot was sharing CoWIN app details when a phone number was entered. The bot was reportedly taken down shortly after it was discovered and covered by news outlets on Monday.

According to Chandrasekhar, the bot was accessing data from a threat actor database. The information available in this database appears to have been sourced from data stolen in the past from an older breach. However, the minister did not share additional details of the previous breach, including whether it was another government entity, whether it was detected before Monday. and whether it was disclosed by CERT-In.

Advertisement

In his tweet, Chandrasekhar also stated that it did not appear that either the CoWIN app or database were directly breached. The minister has not revealed details of how the CoWIN details of users who registered with the platform were available when both the CoWIN app and website were not directly affected by a data breach. 

Advertisement

Meanwhile, the government issued a press release stating that CoWIN data access was available at three levels — the vaccine recipient, the authorised vaccinator, and third-party applications that had API-based (application programming interface) access that only works via user one-time password (OTP) authentication. The government states that the platform logs each attempt by an authorised vaccinator to access the CoWIN system.

The government also states that data from the CoWIN platform could not be shared to an automated bot without an OTP sent to the vaccine recipient as there was no public API with such a level of access. Similarly, the system did not record a recipient's address and only recorded the year of birth for vaccination, unlike the posts shared on social media that show the bot responded with the vaccine recipient's date of birth.  

Advertisement

CoWIN's development team also confirmed that some APIs were shared with third parties like the Indian Council for Medical Research (ICMR) and requests were only accepted by a trusted API whitelisted by the CoWIN application — which suggests there was at least one API that could access data without an OTP. CERT-In has been asked by the Union Health Ministry to investigate the issue and submit a report on its findings, according to the government.


Apple unveiled its first mixed reality headset, the Apple Vision Pro, at its annual developer conference, along with new Mac models and upcoming software updates. We discuss all the most important announcements made by the company at WWDC 2023 on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: CoWIN, Data Breach, India, Cert In
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week: Dude, Nishaanchi, Jolly LLB 3, and More
  2. OnePlus 15R Confirmed to Launch Soon: Know Expected Features
  3. Oppo Find X9 Series Could Launch in India at This Price
  4. Oppo Reno 15 Series to Launch in These Storage Variants, Colourways
  5. Spotify Brings New Premium Plans to India at These Prices
  6. Vivo X300 Series Specs Confirmed, India-Exclusive Red Colour Teased
  7. Marvel Spidey and Iron Man: Avengers Team Up Now Streaming on JioHotstar
  8. Google Could Release Gemini 3 Pro AI Model Alongside Nano Banana 2
  9. Samsung Silently Introduces Galaxy Book 5 Edge 5G With These Features
  10. Honor 500 Pro Specifications Surface Ahead of Launch in China
  1. Google Expands Native Call Recording to Older Pixel Phones With Latest Update
  2. Google DeepMind Introduces SIMA 2, a Gemini-Powered AI Agent That Can Play Video Games
  3. Vivo S50 Series Tipped to Launch Next Month With a Snapdragon Chip
  4. Qualcomm Unveils Dragonwing IQ-X Series Industrial Chipsets, Supports AI Workflows for Smart Industries
  5. Vivo X300 Series Specs Confirmed, India-Exclusive Red Colour Teased
  6. Scammers Exploit Australia’s Cybercrime Portal to Impersonate Police and Steal Crypto, AFP Warns
  7. Ubisoft Delays Earnings Release on Due Date, Requests Trading of Its Shares Be Halted
  8. Claude Jailbroken by Chinese Hackers to Orchestrate First-of-Its-Kind AI Cyberattack
  9. Oppo Reno 15 Series Storage Variants, Colourways Revealed Ahead of China Launch
  10. Centre Notifies DPDP Rules 2025, RTI Amendment 2025 Comes Into Force
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.