shutterstock_490960141-1

Industry News: ESG5

      Know Your Breach: West Bengal Health and Welfare Department

      Feb 26, 2021 10:37:48 AM

      The target: The Health and Welfare Department of West Bengal, India

      The take: 8 million COVID-19 test results including personally identifiable information such as: name, age, address, and positive or negative test results.

      The attack vector: The breach revolves around the health authority’s reporting system, whereby individuals who had been tested for COVID-19 received links by SMS with a unique URL to access their test results by web. It was discovered that there was no authentication in place on the reporting system, and that by incrementing the ID number included in the URL, anyone with internet access could access all test results for the state.

      This example serves once again to highlight the huge risks of adopting a ‘security by obscurity’ model. When administering a public facing portal which provides access to sensitive information, authentication controls are not optional – it is simply inadequate to make all records publicly available and trust that the uniqueness of the URL will protect the sensitive data of organizations or individuals.

      Read more...

      Topics:Know Your Breach

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates