Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Personal data of 16 million Brazilian COVID-19 patients exposed online
#1
https://www.zdnet.com/article/personal-d...ed-online/        Personal data of 16 million Brazilian COVID-19 patients exposed online
Among those affected by the leak are Brazil President Jair Bolsonaro, seven ministers, and 17 provincial governors.

Catalin Cimpanu
By Catalin Cimpanu for Zero Day | November 26, 2020 -- 21:22 GMT (13:22 PST) | Topic: Coronavirus: Business and technology in a pandemic        The personal and health information of more than 16 million Brazilian COVID-19 patients has been leaked online after a hospital employee uploaded a spreadsheet with usernames, passwords, and access keys to sensitive government systems on GitHub this month.

From cancelled conferences to disrupted supply chains, not a corner of the global economy is immune to the spread of COVID-19.

Among the systems that had credentials exposed were E-SUS-VE and Sivep-Gripe, two government databases used to store data on COVID-19 patients.

E-SUS-VE was used for recording COVID-19 patients with mild symptoms, while Sivep-Gripe was used to keep track of hospitalized cases.

The two databases contained sensitive details such as patient names, addresses, ID information, but also healthcare records such as medical history and medication regimes.

The leak came to light after a GitHub user spotted the spreadsheet containing the passwords on the personal GitHub account of an employee of the Albert Einstein Hospital in the city of Sao Paolo.

The user later notified Brazilian newspaper Estadao, which analyzed the data and notified the hospital and the Brazilian Ministry of Health.

Estadao reporters said that data for Brazilians across all 27 states was included in the two databases, including high profile figures like the country's president Jair Bolsonaro, the president's family, seven government ministers, and the governors of 17 Brazilian states.

The spreadsheet was ultimately removed from GitHub while government officials changed passwords and revoked access keys to resecure their systems.

Since the onset of the COVID-19 pandemic, several governments and government contractors have had problems securing their COVID-19-related apps and databases.

Vulnerabilities and leaks were discovered in COVID-19 apps and systems used in Germany [1, 2], Wales, New Zealand, India, and others.

According to research published by Intertrust this September, around 85% of COVID-19 contact tracing apps leak data in one way or another.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Hacker group claims to steal 3 million users’ data from Israeli hiking websites mrtrout 0 1,032 01-22-2022 , 11:03 PM
Last Post: mrtrout
  Over 60 million wearable, fitness tracking records exposed via unsecured database mrtrout 0 603 09-15-2021 , 03:24 AM
Last Post: mrtrout
  38 million records exposed because companies used default configs in Microsoft Power mrtrout 0 595 08-23-2021 , 08:47 PM
Last Post: mrtrout
  Hospitals hamstrung by ransomware are turning away patients mrtrout 0 574 08-17-2021 , 05:44 PM
Last Post: mrtrout
  Unsecured Database Exposes Personal Data of 35M U.S. Citizens mrtrout 0 831 08-04-2021 , 04:37 AM
Last Post: mrtrout

Forum Jump:


Users browsing this thread: 1 Guest(s)