Jio security lapse exposes millions of medical records

(Image credit: Flickr)

A security flaw in the coronavirus symptom checker made by India’s largest telecom operator, Reliance Jio, has exposed the results of millions of users. 

The exposed data includes geo-location of the users along with the self-assessment data of these users. While Jio has pulled down the server, no misuse of the data has been reported yet.

The service was launched in March, right before India's nationwide lockdown was announced, and allowed users to self-screen themselves for the virus. However, an apparent Jio security lapse meant that one of the core databases, where the results were stored, was exposed to the internet without any password protection.

Jio breach

The affected database was then discovered by security researcher Anurag Sen, whose alert prompted the company to take down the server immediately. According to Sen, the database contained data of millions of users right from April 17 till it was finally pulled down on May 1. 

The database reportedly contained information about the devices' operating system, browser version and answers to all the questions asked in the assessment, apart from some generic information.

For some users, the database also had a precise location, possibly linked to those . who had activated the track location feature in their browser. Apart from user data, website error logs and system messages were also found in the database.

According to the report, the database mostly contained the information of users from Indian cities like Mumbai and Pune, however, some records of British and American nationals were also found.

“We have taken immediate action. The logging server was for monitoring performance of our website, intended for the limited purpose of people doing a self-check to see if they have any COVID-19 symptoms," said Jio spokesperson Tushar Pania in a statement.

Via: TechCrunch

Jitendra Soni

Jitendra has been working in the Internet Industry for the last 7 years now and has written about a wide range of topics including gadgets, smartphones, reviews, games, software, apps, deep tech, AI, and consumer electronics.  

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
The Witcher 4
You're probably not playing The Witcher 4 until 2027 at the earliest, per CD Projekt's latest financial update
DeepSeek
DeepSeek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Two Android phones on a green and blue background showing Google Messages
Google Messages just added a fun upgrade to one of its best chat features
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year