Business
EPFO pension scheme holders' data exposed online, claims security researcher
New Delhi, Aug 4
A Ukraine-based cybersecurity researcher and journalist has claimed that about 288 million personal records, containing the full name, bank account number and nominee information of the Employees' Pension Scheme (EPS) holders in the Employees' Provident Fund Organisation (EPFO), were exposed online before being taken off the Internet.
The security researcher's claim about the data exposed online was yet to be verified by the EPFO, national cyber agency CERT-In or the IT Ministry.
Bob Diachenko, cyber threat intelligence director and journalist at SecurityDiscovery.com, claimed that their systems identified two separate IPs with Universal Account Number (UAN) data.
An IP address is a unique address that identifies a device on the internet or a local network. IP stands for "Internet Protocol."
"UAN stands for Universal Account Number and this is an important part of the Indian government registry. UAN is allotted by EPFO, he wrote in a blogpost.
Each record contained personal information, including marital status, gender and date of birth, UAN, bank account number and employment status, among others.
While 280 million records were available under one IP address, the other IP address had about 8.4 million data records publicly exposed, claimed the researcher.
"Given the scale and obvious sensitivity of data, I decided to tweet about it, without giving any details as of source and associated info. Within 12 hours after my tweet both IPs were taken down and now unavailable," Diachenko claimed.
"As of August 3rd, I did not hear back from any agency or company who would claim responsibility for the data found," he added.
According to the security researcher, "both IPs were Azure-hosted and India-based".
"No other information was obtained through reverse DNS analysis as well. Both Shodan and Censys search engines picked them up on August 1st, but it is unknown for how long this information was exposed before search engines indexed them," the security researcher said.
He also tweeted: "[BREACH ALERT] 280M+ records in this Indian database, publicly exposed. Where to report? @IndianCERT?"
Both the IPs have now been taken down from public domain, he informed.
6 minutes ago
NEET-UG exams: Solver gang busted in Bihar, 30 arrested for alleged impersonation
7 minutes ago
Venugopal warning, Sudheeran’s intervention put Satheesan under pressure over budget proposals
9 minutes ago
How did other NEET re-test candidates reach on time? K'taka HM rejects delay controversy
10 minutes ago
Chennai cops arrest 77 people in week-long anti-drug crackdown; seize narcotics, vehicles
10 minutes ago
Nehru’s letters for probing a controversial leader’s tax assessment complaints reflect disturbing facts
12 minutes ago
Kanpur Police arrest man from Rewa over objectionable social media posts against Akhilesh Yadav's daughter
13 minutes ago
Adani's Ambuja Cements joins UK-based Leilac to develop commercial-scale low carbon cement
13 minutes ago
NCW summons Pranit More, Himanshu, Madhur Virli over alleged objectionable social media content against women
15 minutes ago
PIB Fact Check debunks viral claim of NEET-UG 2026 re-exam paper leak on Telegram
15 minutes ago
Kejriwal congratulates Punjab women ahead of July 1 disbursal of funds, calls it world's largest empowerment scheme
16 minutes ago
Hundreds of Kashmiri Pandits reach Mata Kheer Bhawani temple as CM Abdullah, LG Sinha extend greetings on festival
17 minutes ago
Bollywood actor Pankaj Tripathi’s brother injured in attack in Bihar's Gopalganj; probe on
19 minutes ago
Teen kills his elder brother, sister-in-law, nephew with sharp-edged weapon in UP's Gorakhpur
