Provident Fund Data of 28 Crore Indians Leaked By Hackers, Claims Ukraine Based Researcher

The PF data was leaked earlier this month and includes UANs, names, Aadhaar, and bank account details.

Advertisement
By Siddharth Suvarna | Updated: 6 August 2022 19:12 IST
Highlights
  • Leaked data was hosted on Microsoft’s Azure service
  • The researcher informed CERT-In about the leak
  • The data contained Aadhaar and bank details

Details such as UANs, names, Aadhaar details, gender, and bank account details were exposed

Photo Credit: EPFO

Provident Fund (PF) data of about 28 crore Indians was found to have been leaked by hackers earlier this month. A cybersecurity researcher from Ukraine, Bob Diachenko, made the discovery on August 1 and found that details such as Universal Account Number (UANs), names, marital status, Aadhaar details, gender, and bank account details were exposed online. According to Diachenko, he found two different internet protocol (IP) addresses hosting two clusters of leaked data. Both of these IPs were hosted on Microsoft's Azure cloud storage service.

Cybersecurity researcher Bob Diachenko detailed the leak in a post on LinkedIn. On August 2, Diachenko discovered two separate IP clusters of data that contained indices called UAN. Upon reviewing the clusters, he found that the first cluster contained 280,472,941 records, whereas the second IP contained 8,390,524 records.

“After quick review of the samples (using a simple browser), I was sure that I am looking at something big and important”, Diachenko said in his post. However, he was not able to find who owned the data. Both the IP addresses were hosted on Microsoft's Azure platform and were India-based. He wasn't able to obtain other information via a reverse DNS analysis.

Advertisement

The Shodan and Censys search engines from Diachenko's SecurityDiscovery firm found these clusters on August 1. However, it is not clear how long the information was available online. The data could've been misused by hackers to gain access to the PF account. Data such as name, gender, Aadhaar details, could also be used to create fake identities and documents.

Advertisement

The researcher tagged the Indian Computer Emergency Response Team (CERT-In) in a tweet informing them about the leak. The CERT-In replied to his tweet asking him to provide a report of the hack in an email. Both IP addresses were taken down within 12 hours after his tweet. Diachenko says that since August 3, no company or agency has come forward to take responsibility for the hack

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Lenovo Idea Tab Plus Launched in India With 10,200mah Battery: Details
  2. RAM Crisis 2026: 16GB Phones Out, 4GB Models Making a Comeback
  3. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  4. Redmi Note 15 5G Chipset Revealed Ahead of January 6 India Launch
  5. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  6. Motorola Edge 70 First Impressions
  7. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  8. Realme Narzo 90, Realme Narzo 90x Launching Today: All You Need to Know
  9. Oppo Reno 15c With Snapdragon 7 Gen 4 SoC Launched at This Price
  10. Apple Fitness+ Service Is Now Available in India: See Features
  1. Realme Narzo 90, Realme Narzo 90x 5G Launching Today: Know Price in India, Features, Specifications and More
  2. Webb Telescope Discovers Hidden Atmosphere on Molten Super-Earth TOI-561 b Despite Extreme Heat
  3. Astronomers Watch a Dormant Neutron Star Reignite After a Decade of Silence
  4. Predictive Forecasting Tools Can Boost the Success of Clean Energy Investments Worldwide
  5. Chinese Spacecraft Nearly Slammed Into Starlink Satellite, SpaceX Reveals
  6. Clocks on Mars Run Faster Than on Earth, New Study Finds
  7. The Hunting Wives Out on OTT: Know Everything About This American Thriller Mystery Series
  8. All Her Fault Now Streaming on JioHotstar: Know Everything About This Thriller Series
  9. Wednesday Season 3 Set for July 2027 on Netflix: Jenna Ortega Returns as the Iconic Addams Heir
  10. Lakshmi Manchu’s Daksha: The Deadly Conspiracy Available for Streaming on Amazon Prime Video
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.