The Global Pravasi Rishta Portal, the Indian government’s platform for communicating with its overseas population, has suffered a significant data leak that has compromised the sensitive personal information, including passport details, of millions of users.
The Global Pravasi Rishta Portal is a platform run by the Ministry of External Affairs of India. It is used as a tool to communicate among the Ministry of External Affairs, Indian Missions, and the Indian diaspora.
The Cybernews research team recently received a tip that the Global Pravasi Rishta Portal
was leaking the sensitive personal information of its users, which turned out to be correct.
The data leak was a result of manipulating the URL that allowed anyone to access the details of another user. This meant any registered user could access the sensitive personal information of another user by simply changing the URL and the user ID.
The leaked personal information included users’ full names, country of residence, email addresses, phone numbers, passport numbers, and occupation status. According to Cybernews, the leak was a result of poor security measures and a lack of authentication methods.
While the Ministry of External Affairs did not respond when approached by the Cybernews Team, it did fix the leak after several days.
This is the second major data leak suffered by the government of India in the past three months. In October, the Swachhata Platform run by the government of India was hacked into by a hacker named LeakBase who reportedly stole
16 million user records from the platform, including PII details.
The Swachhata Platform is an initiative of the Swachh Bharat (Clean India) Mission, in association with the Ministry of Housing and Urban Affairs of India. The platform helps municipal corporations in the country address citizens’ online complaints and grievances.
According to CloudSEK which discovered the hacker’s post on a dark web cybercriminal forum, the hacker was offering on sale as many as 16 million user records, including Indian citizens’ email addresses, hashed passwords, User IDs, etc.
CloudSEK found that 6GB of data stolen from the platform was shared via a popular file-hosting platform. The stolen information included registered email addresses, password hashes, registered phone numbers, transmitted OTP information, login IP to the platform, MAC address from user’s systems, individual user tokens, and browser fingerprint information.