- Home
- Medical news & Guidelines
- Anesthesiology
- Cardiology and CTVS
- Critical Care
- Dentistry
- Dermatology
- Diabetes and Endocrinology
- ENT
- Gastroenterology
- Medicine
- Nephrology
- Neurology
- Obstretics-Gynaecology
- Oncology
- Ophthalmology
- Orthopaedics
- Pediatrics-Neonatology
- Psychiatry
- Pulmonology
- Radiology
- Surgery
- Urology
- Laboratory Medicine
- Diet
- Nursing
- Paramedical
- Physiotherapy
- Health news
- Fact Check
- Bone Health Fact Check
- Brain Health Fact Check
- Cancer Related Fact Check
- Child Care Fact Check
- Dental and oral health fact check
- Diabetes and metabolic health fact check
- Diet and Nutrition Fact Check
- Eye and ENT Care Fact Check
- Fitness fact check
- Gut health fact check
- Heart health fact check
- Kidney health fact check
- Medical education fact check
- Men's health fact check
- Respiratory fact check
- Skin and hair care fact check
- Vaccine and Immunization fact check
- Women's health fact check
- AYUSH
- State News
- Andaman and Nicobar Islands
- Andhra Pradesh
- Arunachal Pradesh
- Assam
- Bihar
- Chandigarh
- Chattisgarh
- Dadra and Nagar Haveli
- Daman and Diu
- Delhi
- Goa
- Gujarat
- Haryana
- Himachal Pradesh
- Jammu & Kashmir
- Jharkhand
- Karnataka
- Kerala
- Ladakh
- Lakshadweep
- Madhya Pradesh
- Maharashtra
- Manipur
- Meghalaya
- Mizoram
- Nagaland
- Odisha
- Puducherry
- Punjab
- Rajasthan
- Sikkim
- Tamil Nadu
- Telangana
- Tripura
- Uttar Pradesh
- Uttrakhand
- West Bengal
- Medical Education
- Industry
AYUSH Jharkhand allegedly hacked, 3.2 lakh patient records leaked on dark web
New Delhi: Cybersecurity researchers have found that the official website of the Ministry of AYUSH in Jharkhand was breached which has exposed over 3.2 lakh patient records on the dark web, a new report said on Monday.
According to the cybersecurity company CloudSEK, the website's database, amounting to 7.3 MB, holds patient records that include personally identifiable information (PII) and medical diagnoses. The compromised data also contains sensitive information about doctors, including their PII, login credentials, usernames, passwords, and phone numbers.
The data breach was initiated by a threat actor named "Tanaka".
The Ayush website is a critical resource providing information about Ayurveda, Yoga, Naturopathy, Unani, Siddha, and Homoeopathy treatments.
Also read- Delhi AIIMS Hit By Second Cyber Attack In A Year, Security Systems Neutralise Threat
"The link between the compromised data and Ayush Jharkhand's website was established by cross-referencing chatbot and blog post data shared by the threat actor with publicly accessible data on the website," the researchers said.
According to the report, the data breach exposed about 500 login credentials (some in cleartext), contact information of 737 individuals who utilized the "Contact Us" form, 472 records containing PII details of doctors, PII data of 91 doctors, along with the information about where they were posted.
Moreover, the researchers said that the data breach poses significant risks, potentially leading to - account takeovers due to leaked data, brute force attacks exploiting common or weak passwords, and heightened susceptibility to sophisticated phishing attacks.
To address this critical breach, the cybersecurity experts recommended several mitigation strategies such as the implementation of a robust password policy, activation of multi-factor authentication (MFA) across all logins, prompt patching of vulnerable and exploitable endpoints, prohibition of sharing unencrypted secrets on messaging platforms like Slack or WhatsApp, and others.
Also read- Health Ministry Website Allegedly Targeted By Russian Hackers, CERT-IN Support Sought
BA in Journalism and Mass Communication
Exploring and learning something new has always been my sole motto. I completed my BA in Journalism and Mass Communication from Calcutta University. I joined Medical Dialogues in 2022. I mainly cover the latest health news, hospital news, medical college, and doctors' news.