Industry News: Cyber

Know Your Breach: West Bengal Health and Welfare Department

Written by Cybersecurity | Feb 26, 2021 3:37:48 PM

The target: The Health and Welfare Department of West Bengal, India

The take: 8 million COVID-19 test results including personally identifiable information such as: name, age, address, and positive or negative test results.

The attack vector: The breach revolves around the health authority’s reporting system, whereby individuals who had been tested for COVID-19 received links by SMS with a unique URL to access their test results by web. It was discovered that there was no authentication in place on the reporting system, and that by incrementing the ID number included in the URL, anyone with internet access could access all test results for the state.

This example serves once again to highlight the huge risks of adopting a ‘security by obscurity’ model. When administering a public facing portal which provides access to sensitive information, authentication controls are not optional – it is simply inadequate to make all records publicly available and trust that the uniqueness of the URL will protect the sensitive data of organizations or individuals.

Read more...