NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Supreme Court Of India
    Central Bureau Of Investigation (CBI)
    Indian Army
    Indian Railways
    Indian Air Force
    NewsBytes
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout


    India Business World Politics Sports Technology Entertainment Auto Lifestyle Inspirational Career Bengaluru Delhi Mumbai Visual Stories Find Cricket Statistics Phones Reviews Fitness Bands Reviews Speakers Reviews

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
     
    Home / News / India News / Data breach forces EPFO to suspend Aadhaar-seeding services
    India

    Data breach forces EPFO to suspend Aadhaar-seeding services

    Data breach forces EPFO to suspend Aadhaar-seeding services
    Written by Gogona Saikia
    May 02, 2018, 07:07 pm 2 min read
    Data breach forces EPFO to suspend Aadhaar-seeding services

    New information has come to light about a data breach in the EPFO portal, which let subscribers link their Aadhaar to their Universal Account Number (UAN). As a precaution, Aadhaar-seeding services were discontinued on March 22. Though there's no official account of what information was stolen, reports say the leak affected employees' Aadhaar number, name, father's name, PAN, and employment details, among others.

    The EPFO shut down the website once breach was discovered

    BS reports the Intelligence Bureau (IB) informed the Labor and Employment Ministry about the data theft last month. Hackers "exploit(ed) the vulnerabilities prevailing in the EPFO website (aadhaar.epfoservices.com)," central provident fund commissioner VP Joy wrote to Dinesh Tyagi, CEO at Common Service Centre (CSC), manager of the website's server, on March 23. The EPFO shut down the website, urging CSC to secure confidential data.

    Hackers exploited backdoor shells and strut vulnerability

    The IB mentioned two vulnerabilities in the portal. Backdoor shell is when hackers gain access to the front-end of a service through the back-end, meaning "they could get administrative privileges and manipulate systems," a security-researcher explained. Meanwhile, Apache Struts is a Java-based platform used to develop web applications. Breach in struts means "(hackers) could remotely run code on machines at EPFO without much difficulty."

    'There's nothing to be concerned about,' EPFO insists

    The EPFO has put the responsibility on the CSC, insisting "the news (of the breach) is relating to the services through CSC and not EPFO Software or data center." "No confirmed data leakage has been established or observed so far." "As part of data security and protection, EPFO has taken advance action by closing the server and host service through CSC pending vulnerability checks."

    Currently, Aadhaar-seeding being done through other modes

    For now, Aadhaar-seeding is ongoing through other modes, like the government's mobile app Umang. The EPFO has issued 13cr UAN till now to formal sector workers; 3.45cr out of 4.7cr active PF accounts have been linked to Aadhaar.

    Share this timeline
    Facebook
    Whatsapp
    Twitter
    Linkedin
    Latest
    EPFO
    Aadhaar Card
    Intelligence Bureau
    Data Leak

    Latest

    WHO has good news for patients battling obesity; Know why World Health Organization
    IPL 2023: Five finishers to watch out for Andre Russell
    Respect territorial integrity: Ajit Doval slams China at India-led SCO Ajit Doval
    Google will now notify you about extreme heat conditions Google

    EPFO

    Coronavirus impact: EPFO to pay 8.5% interest in two installments Employees Provident Fund Organization (EPFO)
    #TechBytes: How to withdraw PF using an app Aadhaar Card
    With reduced EPF contribution, your take-home salary will now increase Nirmala Sitharaman
    Five ways to check your Employees' Provident Fund balance India

    Aadhaar Card

    PAN-Aadhaar linking deadline extended to June 30, 2023 PAN Card
    What is Baal Aadhaar card and how to get it Unique Identification Authority of India
    Why do you need to link PAN card with Aadhaar PAN Card
    The different types of Aadhaar issued by UIDAI: A guide Aadhaar

    Intelligence Bureau

    Delhi: 6 arrested with over 2,000 cartridges before Independence Day Delhi Police
    IB warns of terror strike in Delhi on Independence Day Delhi
    Naga Peace talks in rough weather, PM involves IB Director Narendra Modi
    Tahir Hussain confesses to role in February Delhi violence: Police Delhi Police

    Data Leak

    Ex-employee stole staff data of thousands, says Credit Suisse Data privacy
    Indian social media app Slick exposes user data of minors Social Media
    Indian Railways data breach: Data of 30mn users on sale Indian Railways
    How to safeguard WhatsApp chats from a data breach? WhatsApp

    Love India News?

    Subscribe to stay updated.

    India Thumbnail
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2023