What's new

NADRA, Police and Telcos data being sold publicly on Facebook

Ali Tariq

SENIOR MEMBER
Joined
Mar 17, 2017
Messages
2,749
Reaction score
7
Country
Pakistan
Location
Pakistan
By Asra Rizwan on May 7, 2018 - Like us now!

51db119751255-790x474.jpg


Sensitive information of millions of Pakistani citizens has been compromised in what may be dubbed as the biggest data breach of Pakistan.



In August last year, a local media outlet reported that Punjab Information Technology Board (PITB) has exposed sensitive data of thousands of individuals that comprised of CNICs and scanned copies of personal documents. According to PITB, a bug that attributed to this exposition was taken care of, however, no comments were made on the possession of leaked data.

Nine months later, PITB is yet again in deep waters after it was revealed that sensitive information acquired through various PITB portals is now being sold publicly. This information comprises of personal and family data held by NADRA, criminal records tracked by the Police and call data recorded by telecom companies.

According to the reports and evidence received by TechJuice from two separate entities, the sensitive information compromised include:

  • CNIC Information
  • SMS & Call Records
  • NADRA Family Tree Data
  • Criminal Records
  • Rent Tentee & Hotel Visitor Information
  • SMS Spoofing services
  • Offline Databases of Registered Mobile Users
How did it happen?
The breach traces back to when PITB gained access to NADRA’s server after it was allowed to digitize the data of citizens by linking CNIC numbers to various public departments. This data could only be accessed through authorized users, however, it is now being alleged that these officials shared their credentials which were used for extraction and trading of sensitive information of Pakistani citizens.

A sample unprotected API called data from the PITB apps developed and hosted in PITB data center. The call makes it evident that no security authentication was put in place.




Click to View all images in full size.

Desktop applications have also been developed to connect the offline databases and extract data to be sold online.



In addition to this, a data archive of telecom companies is also publicly available that does not only have information about call records but the address and CNIC number of the user registered against the SIM.



How is this data being publicly sold on social media?
As an aftermath of this, data was extracted and is now being sold publicly on Facebook and Whatsapp groups for as low as PKR 100. When TechJuice viewed one of these public groups, we were horrified to see that some of the members were running promotional campaigns for a limited time to share data for free. Complete NADRA family trees were also being sold on these groups.




Click to view full image.

Which applications compromised this data?
One of the portals developed by PITB, Agriloan allowed users to extract a citizen’s data by their CNIC number. Once the number is fed into the system, it gives out the person’s name, picture, date of birth, past and permanent locations.

For another app, Police Toolkit used by Punjab Police, the credentials are being sold and personal information is being leaked such as criminal record, driving license information, FIRs, vehicle ownership and verified SIM.



According to the reports, Pak vs World XI mobile app also fell victim of data breach and gave access to the information of hotel check-ins and criminal records.



What do NADRA and PITB have to say about this breach?
In conversation with a local media outlet, NADRA has revealed that they have been aware of the situation and pinned the responsibility on PITB for the safety of data. A deadline was already declared by NADRA for PITB to resolve this breach. NADRA has frequently mentioned the lack of security measures put in by PITB to protect the data.

The same media outlet also reached out to Dr. Umar Saif, who said that they are actively revoking the access of their portals and applications, while also launching inquiries and action against alleged personnel. He said that all instances have been resolved and they are actively blocking any breach of authorization. However, he did not comment on the absence of security protocols that were not deployed by PITB in the apps and portals under question.

TechJuice has reached out to NADRA for a comment. We also reached out to the InfoSec team who shared the details with us as #PITBLeaks, however, they declined to comment further.

[Update] Chairman PITB, Dr. Umar Saif has recently tweeted on the matter but it seems that PITB is also unaware of the culprits behind this data violation.


Umar Saif

✔@umarsaif


Punjab Government will be taking legal action for whoever is responsible for making and propagating false, unfounded and malicious content against government IT systems on whatsapp, facebook and twitter.

6:29 PM - May 7, 2018
Twitter Ads info and privacy




On the other hand, InfoSec Team has also launched a campaign on Twitter;




#PITBLeaks@pitbleaks


#NADRA, police, and telecom data of citizens got leaked in the biggest #cybersecurity #breach in the history of #Pakistan. Everything from your address, call records, police records, driving license database, even the hotels u stayed in

Thanks to #PITB & #DrUmarSaif. #PITBLeaks

7:52 AM - May 7, 2018
Twitter Ads info and privacy




How does it impact Pakistani citizens?
The scale of this breach poses dangers for each citizen whose information has been compromised. In the hands of criminals, anti-state actors and terrorists, the nonrenewable information puts the safety of every Pakistani citizens at risk. The question is, how will NADRA and PITB be held accountable for the breach? How will the perpetrators be tracked and brought to justice? Most importantly, how can the leaked information be prevented from usage and modification? While we seek answers to this question, a criminal application has already extracted data from PITB and connected with its other applications available on the PlayStore.



Source: TechJuice
 
Last edited by a moderator:
I bid one Dollar for Khans Blackberry
 
Punjab seems to be stuck in agarian backwardness..they should be kept away from IT..as it can ruin citizen record fo entire country..it is good that Sindh Govt has not taken any such initiative..better to remain backwards than have a crippled system..
 
The problem is much bigger than this,
There are no laws governing the use and exposure of data, even when it is not leaked.

Example, the data your bank has on you, can be viewed by anyone within the bank and then passed on to criminals.
The law does not tell banks how to solve this issue.

within NADRA, even if the data isn't leaked out, there is very little NADRA can do to stop an "insider" compromise.

Unfortunately, people who are responsible for these systems have very little exposure or training.
Most of them are typical babu types, dumb fucks.
 
Rehman Malik has turned NADRA into RAW's largest operation in Pakistan.
Only way forward is to arrest all the staff hired by Rehman Malik and hired by staff hired by Rehman Malik.
 
corrupt system till core
 
Bastard Dr Umar Saif is planted mole and for compromising the data this son of a bitch is being made UNESCO chair for ICTD.
 
Bastard Dr Umar Saif is planted mole and for compromising the data this son of a bitch is being made UNESCO chair for ICTD.

I don't think it's guys fault, you know how competent and honest people we got working in all departments. Can be anyone in hierarchy leaking sensitive information. The guy is genius and have accomplished quite much under his belt in a very young age.
 
Poorly coded APIs ..... interface connecting diff Gov database/website ... a welcome message for hackers to breach the data...
 
block chain, anyone ?
 
I don't think it's guys fault, you know how competent and honest people we got working in all departments. Can be anyone in hierarchy leaking sensitive information. The guy is genius and have accomplished quite much under his belt in a very young age.
I have heard that there is more to this young guy's achievements.
 
They should at least come out admit their mistake and apologize...Every now and then their people are involved in every crime imaginable: Selling data/ Making fake CNIC/ Making dual CNIC!

Or the least they can do is not hire idiots who either cant type properly or people who have no shame or understanding of how precious their post and responsibility is!

The system is far from perfect and definitely a burden esp when it is putting the citizens in danger or even beaching the confidentiality!
 
Back
Top Bottom