Sensitive data of 288 million EPFO pension scheme holders exposed online, claims security researcher
The security researcher's claim about the data exposed online was yet to be verified by the EPFO, national cyber agency CERT-In or the IT Ministry. Bob Diachenko, cyber threat intelligence director and journalist at SecurityDiscovery.com, claimed that their systems identified two separate IPs with Universal Account Number (UAN) data.
While 280 million records were available under one IP address, the other IP address had about 8.4 million data records publicly exposed, claimed the researcher. Pic: epfindia.gov.in