EPFO maintained that no confirmed data leakage was established, Cert-In’s probe suggests otherwise, pointing to a breach of EPFO systems in 2018
A recent investigation by a cybersecurity agency in New Delhi revealed that a data breach in 2018, affecting the systems of the Employees’ Provident Fund Organisation (EPFO) and exposing the personal data of millions of Indians, was linked to a Chinese cyber agency. Initially, the EPFO denied any compromise, blaming the vulnerability to the systems of the Common Service Centre (CSC). However, leaked documents on GitHub suggested otherwise, compelling the Indian Computer Emergency Response Team (Cert-In) to investigate further.
The leaked database allegedly contains information from various Indian institutions, both government and private, including EPFO, BSNL, Air India, and Reliance. Cert-In’s preliminary findings indicate that the EPFO data in the documents dates back to the 2018 breach, despite initial claims by EPFO officials shifting blame to the CSC software.
While EPFO maintained that no confirmed data leakage was established, Cert-In’s probe suggests otherwise, pointing to a breach of EPFO systems in 2018. This incident adds to a series of cybersecurity-related challenges faced by India, including a recent attack on AIIMS Delhi’s systems in 2022.
“Cert-In had carried out a preliminary probe into the claims, and it appears that the EPFO data present in the documents is from 2018 when its systems were impacted,” a senior government official said. At the time of the breach in 2018, a senior EPFO official stated that the alleged data leak occurred “on the CSC software” rather than “on the EPFO server or software.” However, a CSC representative refuted the claims, stating that the concerned application was on the EPFO server and that the CSCs had nothing to do with the incident.
“No confirmed data leakage has been established or observed so far. As part of the data security and protection, EPFO has taken advance action by closing the server and host service through Common Service Centres pending vulnerability checks,” the EPFO had said
According to the 2023 India Threat Landscape Report by Cyfirma, India is the most targeted country for cyberattacks globally, underscoring the urgency to bolster cybersecurity measures. In response, the government has developed the National Cybersecurity Reference Framework (NCRF), recommending the use of domestically developed security products and services, particularly in critical sectors like banking, telecom, and energy.

