NEW DELHI: The personal and professional details of about 2.7 crore members registered with the retirement fund body Employees Provident Fund Organisation (EPFO) have been exposed to data theft.

In a letter to the Ministry of Electronics and Information Technology, the Central Provident Fund Commissioner has written that hackers have stolen data from the Aadhaar seeding portal of EPFO. He has also asked the ministry's technical team to plug vulnerabilities on the portal aadhaar.epfoservices.com that has now been temporarily shut. The portal links the Aadhaar number of employees with their provident fund accounts.

In the letter marked "secret", the commissioner wrote that the Intelligence Bureau (IB) had informed them of "hackers exploiting the vulnerabilities prevailing in the website (aadhaar.epfoservices.com) of EPFO."

Details of the scale of the breach are not known but the website contains information like the names and addresses of EPF subscribers besides their employment history.

"Each person contributes 12% of salary as provident fund, so salary details could also have been stolen. Also the bank account numbers as people tend to withdraw their PF," said cybersecurity expert Anand Venkatnarayan.
 

Hackers exploiting vulnerabilities, EPFO commissioner wrote to the government

A total of 114 government websites were hacked between April 2017 and January 2018, the Ministry of Electronics and IT told Lok Sabha in March.

On April 6, amidst reports that several websites including those of the ministries of defence, home and law had been hacked, the government had dismissed them as hardware problems.

Cyber security experts say monitoring is a big issue with government websites.

"The reason why these breaches happen is that the government is always reactive instead of being proactive. We never take security measures in initial stages. There should be a proper bug reporting mechanism also so that we can report to the government and they can secure their database," said Kshitij Adlakha, CEO of Cybersecurity firm Secugenius.

"No confirmed data leakage has been established or observed so far. As part of the data security and protection, EPFO has taken advance action by closing the server and host service through CSC (Common Service Centre) pending vulnerability checks, EPFO said in a statement.

The head of the Computer Emergency Response team of the Ministry of Electronics and IT, when contacted by NDTV, remained unavailable.

The body that governs Aadhaar, UIDAI, has clarified that it has nothing to do with the alleged data breach from aadhaar.epfoservices.com. "This matter does not pertain at all to any Aadhaar data breach from UIDAI servers. There is absolutely no breach into Aadhaar database of UIDAI. Aadhaar data remains safe and secure," it said.

Courtesy:NDTV

Let the Truth be known. If you read VB and like VB, please be a VB Supporter and Help us deliver the Truth to one and all.



Berhampur (Odisha), Nov 2: Five MBBS fourth-year students of government-run MKCG Medical College here were expelled from the hostel for allegedly ragging juniors, an official said on Saturday.

Earlier the five students have been rusticated from the campus for six months. The punishment was imposed as per the decision of the anti-ragging committee meeting held on Wednesday, the official said.

"The anti-ragging committee has taken such a hard decision to arrest further occurrence of ragging incidents in the medical college campus," said SP (Berhampur) Sarvan Vivek M, who is one of the members of the anti-ragging committee of the college.

Suchitra Dash, in-charge Dean of the college, however, declined to comment on the development.

The SP said they were also investigating separately against these students based on the FIR lodged. The statement of the students have been recorded by the police on Friday, he said.

While one second-year MBBS student has given a written complaint to the college authorities alleging ragging by senior students, three other complaints of ragging were lodged by parents of the students with the National Medical Council (NMC).

The NMC had directed the college authorities to inquire into the allegations and take action against the students.

After receiving the complaints from the NMC, the anti-ragging committee of the medical college inquired into the matter.

In February this year, the medical college authorities had suspended two fourth-year MBBS students for two months for ragging a second-year student.