Skip to content

Star Health and Allied Insurance data breach case reaches Supreme Court

Star Health and Allied Insurance data breach case reaches Supreme Court

India’s Supreme Court has refused to interfere with criminal proceedings against cybersecurity researcher Himanshu Pathak over allegations that he accessed and downloaded sensitive customer data from Star Health and Allied Insurance Company without authorisation.

The court dismissed Pathak’s Special Leave Petitions challenging a Madras High Court judgment that had declined to quash the case. It allowed him to raise his arguments before the trial court and made permanent the interim bail granted on August 6.

Star Health alleges that Pathak accessed and downloaded around 8,000 files containing customers’ personal, health and financial information. The insurer also claims he later sought to pressure the company by referring to possible publication of information while offering cybersecurity services.

Pathak disputes those allegations. He says he identified serious vulnerabilities in Star Health’s systems, reported them to the insurer and a cybersecurity platform, and sought corrective action without intending to misuse customer information.

A bench comprising Chief Justice Surya Kant and Justices Joymalya Bagchi and V. Mohana said Pathak’s claim of bona fide security research involved factual questions that should be assessed during the criminal proceedings rather than decided at the quashing stage.

The court had earlier directed Pathak to appear before the XI Metropolitan Magistrate in Chennai and furnish bail bonds. In its latest order, it declined to entertain his petitions but preserved his right to raise his defence before the trial court.

Pathak cites closure of separate Policybazaar case

Advocate Prashant Bhushan, appearing for Pathak, challenged Star Health’s description of his client as a habitual offender. The insurer had referred to another FIR filed against Pathak following a complaint by Policybazaar.com involving similar allegations.

Bhushan told the Supreme Court that Star Health had not disclosed that police later closed the Policybazaar case. Investigators found that Pathak had informed the company about security vulnerabilities and leakage of sensitive customer information.

Bhushan argued that the earlier investigation supported Pathak’s account of his work as a cybersecurity researcher. He said Pathak had reported vulnerabilities to other organisations, including Punjab National Bank, Vodafone and CDSL, and those organisations had acknowledged the reports and taken corrective action.

He maintained that Pathak never published customer data or supplied it to unauthorised parties. According to the defence, downloading material from Star Health’s systems was intended to demonstrate the extent of the vulnerability rather than exploit the information.

Supreme Court questions downloading of customer files

The bench focused on the alleged downloading of thousands of customer files and questioned whether accessing that volume of information was necessary to demonstrate a security weakness.

The judges drew a distinction between notifying a company that its system is vulnerable and removing sensitive information from its database.

The court observed that once personal data is downloaded, the privacy interests of the individuals whose records are involved become part of the case.

Bhushan argued that demonstrating simple access would not necessarily establish the scale of the vulnerability. He said the downloaded material was used to show Star Health the extent of the problem and was not publicly disclosed.

The bench indicated that these competing accounts required examination of evidence. It questioned whether the factual dispute over Pathak’s intentions and conduct was suitable for determination while considering a request to quash the prosecution.

Star Health points to emails and proposed cybersecurity fees

Senior Advocate S. Muralidhar, representing Star Health, relied on communications between Pathak and the insurer. He argued that the emails went beyond a routine vulnerability disclosure and needed to be examined together with the alleged downloading of customer data.

One email referred to plans to publish articles about the security issues through national and international publications after the vulnerabilities were fixed. Star Health characterised the reference to publication as pressure on the company rather than a standard disclosure process.

Muralidhar also referred to communications in which Pathak allegedly proposed charging $65,000 for an attack-surface analysis and $3,000 per month for maintenance. He argued that the payment discussions, the alleged possession of thousands of customer files and the references to publication supported the prosecution’s case.

Pathak’s defence rejected the allegation of extortion. Bhushan said the chronology showed that Pathak first identified the vulnerability, informed Star Health and sought remediation, with discussions about paid cybersecurity work coming later.

Star Health also told the court that its systems retained records and metadata showing which files had been accessed. According to the insurer, those records would allow the extent of the alleged access and downloading to be examined during the trial.

The Supreme Court did not rule on whether Pathak’s conduct amounted to legitimate cybersecurity research or criminal activity. It left those questions for the trial court, while allowing the prosecution arising from Star Health’s complaint to continue.