The Ministry of Health of Northern Ireland (DoH) temporarily suspended its operation this week online vaccination certificate service COVID-19 COVIDCert - after data breach. The Ministry reported that to some users of the application COVIDCert NI other users' data appeared. Currently, both the online service and the corresponding mobile app are not accessible.
COVIDCert allows fully vaccinated individuals in Northern Ireland to obtain a digital certificate confirming COVID-19 vaccination status. This is a separate system from NHS COVID Pass used in England and Wales, and a similar press service "Vaccination passport" used by the Scottish Public Health Service.
The Northern Ireland service is available through the website covidcertni.nidirect.gov.uk or mobile app for Android and iOS users.
The following error message is displayed to those who visit the service: "Our services are not available at this time. We are working to restore all services as soon as possible. Please try again soon. "
The Northern Ireland Department of Health immediately referred the matter to Office of the United Kingdom Information Commissioner (ICO), after he discovered it.
DoH, he said, on the 27th of July, in a relevant announcement, the following: "The Ministry of Health takes the confidentiality of citizens 'data very seriously and has contacted the Office of the Information Commissioner (ICO), as part of due diligence in protecting citizens' data. "Immediate action has also been taken to temporarily abolish part of the identity management service."
In addition, the Ministry has published a list of those not affected by this security incident:
- The applicants (those who apply from now until 31/07) who already have their certificate will not be affected - their applications or forms are still running.
- The candidates (until 31/07) who have applied through the online portal to download PDF that they have not yet received, will not be affected - the PDF will be delivered.
- The candidates (until 31/07) who have applied using the “COVIDCert NI” application for a digital certificate they have not yet received will not be affected - a PDF will be sent to them as a temporary step.
In addition, the Ministry noted that some individuals who have already applied for a digital certificate or whose identity checks are pending will also not be affected.
The following can continue to use the services normally once they are restored:
- The candidates (until 31/07) who have applied for a digital certificate receiving a PDF copy will be able to log in and download a digital version once the issue is resolved.
- The candidates currently authenticated in the NIDirect workflow can continue. Once their identity has been successfully verified, they should pause as we fix the above problem.
Some users may realize that they can not log in through their NIDirect account, as they have been "locked out" due to a technical problem.
This data incident, though seemingly minor, comes at a time when there is a lot of control but also concern about COVID-19 vaccination passports. The hackers aim, successfully many times, critical healthcare systems, and then ask huge amounts of ransom.
Source of information: bleepingcomputer.com