Site navigation

Covid Testing Megalab Leaves Private User Data Vulnerable

David Paul

,

megalab data breach
New research from Which? has found a vulnerability on French Covid test firm Biogroup’s systems, putting UK traveller data at risk.

Covid testing firm Biogroup has accidentally made the private data of travellers freely available on its website after failing to add password protection.

Which? discovered the vulnerability after incorrectly typing one digit when inputting the reference number for a Covid test.

The breach meant that data on up to 5,700 other users’ details became visible, including names, addresses, telephone numbers and dates of birth.

The available details are commonly used in identity fraud, and the open availability has left them vulnerable to theft from outside threat actors.

According to the Information Commissioner’s Office (ICO), day two Covid-19 test providers must obtain private information of ethnicity and vaccination status, as well as passport numbers, addresses and phone numbers, meaning Biogroup would hold a substantial amount of data on Covid its users.

The France-based company has previously described its west London ‘Megalab’ as one of the largest Covid-testing laboratories in the UK, providing PCR and rapid lateral flow tests to the British public.

Which? said it warned Biogroup about the vulnerability on the 14th of September and 17th of September. The firm said it had “resolved the problem” and reported it to the ICO.

In a response to contact by Which? the company said: “Biogroup has rectified the root cause of the incident and will continue to pressure test its software systems to ensure no issues exist in the future.

“No system is infallible, and we will continue to learn and improve ours through our customer engagement. This is our guarantee to our customers.”

The firm also conducted an internal investigation into the breach and concluded that there were no signs that the data had been accessed by threat actors.


Recommended


As we emerge from the pandemic, the cybersecurity landscape around data breaches reveals a concerning lack of safety measures to protect user data across industries.

In ethical hacker platform HackerOne’s Hacker Report released earlier in 2021, the firm found an increase in submitted vulnerability reports last year.

According to the survey of 4,000 global hackers, carried out between December 2020 and January 2021, there was a 63% increase in the number of researchers submitting reports across 20 different vulnerability categories: an increase of 143% since 2018.

Over the last 18 months, cyber-criminals have stepped up attempts to steal valuable data, using the pandemic as a weapon against unsuspecting victims.

Cybersecurity specialists Barracuda Networks previously found that the number of vaccine-related spear phishing email attacks increased by 12% between October and November 2020, rising to 26% by the end of January this year.

Early in the pandemic, malicious actors working on behalf of foreign states were found to have attempted the theft of Covid-19 research from British universities, according to cybersecurity experts.

The cyberattacks were traced back to both Russia and Iran, but experts say that China is potentially making similar attempts.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data