NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout

    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Inspirational
    Career
    Bengaluru
    Delhi
    Mumbai

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / India News / Data breach forces EPFO to suspend Aadhaar-seeding services
    Next Article
    Data breach forces EPFO to suspend Aadhaar-seeding services

    Data breach forces EPFO to suspend Aadhaar-seeding services

    By Gogona Saikia
    May 02, 2018
    07:07 pm

    What's the story

    New information has come to light about a data breach in the EPFO portal, which let subscribers link their Aadhaar to their Universal Account Number (UAN).

    As a precaution, Aadhaar-seeding services were discontinued on March 22.

    Though there's no official account of what information was stolen, reports say the leak affected employees' Aadhaar number, name, father's name, PAN, and employment details, among others.

    About

    The EPFO shut down the website once breach was discovered

    BS reports the Intelligence Bureau (IB) informed the Labor and Employment Ministry about the data theft last month.

    Hackers "exploit(ed) the vulnerabilities prevailing in the EPFO website (aadhaar.epfoservices.com)," central provident fund commissioner VP Joy wrote to Dinesh Tyagi, CEO at Common Service Centre (CSC), manager of the website's server, on March 23.

    The EPFO shut down the website, urging CSC to secure confidential data.

    Vulnerability

    Hackers exploited backdoor shells and strut vulnerability

    The IB mentioned two vulnerabilities in the portal. Backdoor shell is when hackers gain access to the front-end of a service through the back-end, meaning "they could get administrative privileges and manipulate systems," a security-researcher explained.

    Meanwhile, Apache Struts is a Java-based platform used to develop web applications.

    Breach in struts means "(hackers) could remotely run code on machines at EPFO without much difficulty."

    EPFO

    'There's nothing to be concerned about,' EPFO insists

    The EPFO has put the responsibility on the CSC, insisting "the news (of the breach) is relating to the services through CSC and not EPFO Software or data center."

    "No confirmed data leakage has been established or observed so far."

    "As part of data security and protection, EPFO has taken advance action by closing the server and host service through CSC pending vulnerability checks."

    Do you know?

    Currently, Aadhaar-seeding being done through other modes

    For now, Aadhaar-seeding is ongoing through other modes, like the government's mobile app Umang. The EPFO has issued 13cr UAN till now to formal sector workers; 3.45cr out of 4.7cr active PF accounts have been linked to Aadhaar.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    EPFO
    Aadhaar Card
    Intelligence Bureau
    Data Leak

    Latest

    Indian companies advise remote work amid escalating tensions with Pakistan India
    Chandigarh bans hoarding of essential commodities amid India-Pakistan tensions Chandigarh
    TVF postpones 'Very Parivarik 2' amid India-Pakistan tensions Indian Army
    'Soldiers at war..and you want...rest?': Court slams lawyers observing holiday Haryana

    EPFO

    Here's how you can check your PF account balance Employees' Provident Fund Organisation (EPFO)
    PF account to be transferred, not closed, upon job change India
    Here's how you can check your PF account balance India
    You can now link UAN with Aadhaar number online India

    Aadhaar Card

    Bengaluru Traffic Police goes online: Will accept vehicle-documents on app Karnataka
    Online registrations begin for NEET 2018 Education
    Gurugram: Pregnant-woman not carrying Aadhaar forced to deliver outside hospital Gurugram
    How safe and secure is Aadhaar? All myths busted India

    Intelligence Bureau

    Alleged Wani successor Sabzar Ahmad Bhat listed as 'A-category' militant Hizbul Mujahideen
    Call from U.S. warns of blasts in NCR Delhi Police
    India's budget and the rituals that kick it off Narendra Modi
    NGO funding: Government submits stringent draft guidelines to Supreme Court India

    Data Leak

    This WhatsApp flaw lets hackers, stalkers "monitor" your activities! WhatsApp
    Australia loses sensitive defense data in an 'extreme' hacking incident Australia
    Bank details of Indians are available online for Rs. 500 India
    Aadhaar mess-up: 800 families of Uttarakhand-village born on January 1 India
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025