Context:

  • Recently, the Ministry of Corporate Affairs fixed a critical vulnerability in its online portal months after a cybersecurity researcher reported the vulnerability to the Computer Emergency Response Team of India (CERT­In).
  • The critical vulnerability exposed personal details like Aadhaar, PAN, voter identity, passport, date of birth, contact number and address of more than 98 lakh directors of Indian companies.
  • The vulnerability also exposed the personal data of top industrialists, celebrities, and sports personalities in the country.

What is Personally Identifiable Information?

  • Personally Identifiable Information (PII) is any data or information which is maintained by an organisation or agency that can potentially be used to identify a specific individual.
  • This could include various type of information such as Aadhaar, PAN, voter identity, passport, date of birth, contact number, communication address, and biometric information.
  • The contents of PII vary depending on an individual’s home country.
  • However it is important to note that the non­PII in tandem with additional information can be used to identify an individual.
  • Non­PII information includes photographic images (especially of the face or other identifying characteristics), place of birth, religion, geographic indicators, employment information, educational qualifications, and also medical records.
  • All the above information can be used to identify individuals accurately.
  • And while access to one set of PII may be enough to compromise online security, access to multiple databases can be actually used to identify and target individuals.

What is the difference between sensitive and non­sensitive PII?

  • Non­sensitive PII is publicly available information which can be stored and transmitted unencrypted.
  • This includes information like zip code, race, gender, and religion.
  • They cannot be used to accurately identify an individual.
  • But Sensitive PII when exposed can be used to identify individuals and potentially cause harm.
  • Some of the most important components that constitute sensitive PII are stored by the employers, government organisations, banks, and other digital accounts which are used by individuals.

What are the risks of PII exposure?

  • Cyberattacks and weaknesses in digital infrastructure can lead to the exposure of citizens’ Personally Identifiable Information.
  • Threat actors can gain access to exposed PII and misuse the same to launch targeted attacks on individuals.
  • These attacks could range from phishing attacks with messages curated with the sensitive information, to fraudulently opening bank accounts, and siphoning funds from accounts allotted to beneficiaries of government welfare programmes.
  • Threat actors may also use such information to obtain cellular connections, credit cards, and use them to compromise the security of an individual’s digital accounts.
  • Threat actors are also known to sell the exposed PII information on the dark web.

What are the recent events where PII was compromised?

  • In 2023 reports popped up that a bot on Telegram was returning the personal data of Indian citizens who registered with the COVID­19 vaccine intelligence network (CoWIN) portal for vaccination purposes.
  • A similar data breach was also noted when an American cybersecurity company said that the PII of 815 million Indian citizens, including Aadhaar numbers and passport details, were being sold on the dark web.
  • Also a cybersecurity company known as Resecurity has said that it contacted multiple victims who verified the validity of their data.
  • However the government of India denied allegations of a biometric data leak, as well as a breach in the CoWIN portal.
  • But the government launch an investigation into the allegations that led to the arrest of a man in Bihar along with a juvenile in June 2023.
  • A data breach was also reported in the RailYatri platform during last year January.

How can one protect PII?

  • It is important to note that individuals may not be able to prevent leaks in databases of government organisations or service providers.
  • However they can take steps to make sure that their PII is not readily available to threat actors.
  • Using the safe browsers is one such step.
  • Some browsers use a lock symbol in the URL bar to signify that a website is secure.
  • One should use a VPN when accessing sensitive information using public networks.
  • A VPN helps to protect PII and other vital data by securing your online connection from prying eyes on public networks.
  • One must keep on eyes on PII like Aadhaar, passport, PAN, Voter ID, and other important proofs of identity.
  • One should avoid sharing or accessing images or details of identity documents through unknown devices.