Star Health Confirms Cyber Attack: Personal Data Of Millions Potentially Exposed
Star Health and Allied Insurance revealed on October 9 that they were the victims of a cyber attack , resulting in “unauthorised and illegal access to certain data.” Despite this breach, the company assured that its operations were not affected.
In a statement, the company said, “A thorough and rigorous forensic investigation, led by independent cybersecurity experts, is underway, and we are working closely with government and regulatory authorities at every stage of this investigation, including by duly reporting the incident to the insurance and cybersecurity regulatory authorities apart from filing a criminal complaint.”
Based in Chennai , Star Health provides coverage for over 17 crore Indians through a network that includes 14,000 hospitals and 850 offices. Besides health insurance, it also offers personal accident and travel insurance policies.
Though the exact scope of the breach, including whether customer data was accessed, remains unclear, some crucial details about the hack have emerged, highlighting a significant risk to millions of Indians.
Leaked Data and Telegram Chatbots
According to a Reuters report, hackers leaked the personal information of over 3.1 crore Star Health policyholders, along with details on 5.8 million claims, via Telegram chatbots. The data exposed includes phone numbers, addresses, tax details, copies of ID cards, and medical reports.
Hackers reportedly shared samples of the stolen data through Telegram chatbots with potential buyers. While Telegram took down the bots a day later, after initially labeling them as ‘Scam,’ hackers have previously used such bots to sell stolen data, including sensitive personal information from Indian citizens who signed up for the CoWIN portal.
Following the removal of the bots, hackers allegedly created a website where they offered the entire Star Health dataset for $150,000 (around Rs 1.25 crore).
The website’s message claimed, “I am leaking all Star Health India customers and insurance claims sensitive data. This leak is sponsored by Star Health and Allied Insurance Company, which sold this data to me directly. You can check the authenticity of the data in the Telegram bots below and read about how they sold it in the section below.”
Furthermore, the hackers accused Star Health’s Chief Information Security Officer ( CISO ) of selling them the data.
Star Health’s Response to the Allegations
In response to the breach, Star Health took legal action, filing a case against Telegram for allowing its platform to be used in selling stolen data. The company also filed a complaint against Cloudflare, accusing the US-based firm of hosting the hackers’ website.
However, Cloudflare has denied any involvement, stating that they did not host the domains in question.
Addressing claims about their CISO, Amarjeet Khanuja, Star Health said, “We also want to categorically mention that our CISO has been duly co-operating in the investigation, and we have not arrived at any finding of wrongdoing by him till date. We request that his privacy be respected as we know that the threat actor is trying to create panic.”
In a statement, the company said, “A thorough and rigorous forensic investigation, led by independent cybersecurity experts, is underway, and we are working closely with government and regulatory authorities at every stage of this investigation, including by duly reporting the incident to the insurance and cybersecurity regulatory authorities apart from filing a criminal complaint.”
Based in Chennai , Star Health provides coverage for over 17 crore Indians through a network that includes 14,000 hospitals and 850 offices. Besides health insurance, it also offers personal accident and travel insurance policies.
Though the exact scope of the breach, including whether customer data was accessed, remains unclear, some crucial details about the hack have emerged, highlighting a significant risk to millions of Indians.
Leaked Data and Telegram Chatbots
According to a Reuters report, hackers leaked the personal information of over 3.1 crore Star Health policyholders, along with details on 5.8 million claims, via Telegram chatbots. The data exposed includes phone numbers, addresses, tax details, copies of ID cards, and medical reports.
You may also like
- Coast Guard airlifts ailing seafarer from ship off Gujarat coast despite rough seas, adverse weather
- Jammu and Kashmir: Mehbooba faces heat over Jantar Mantar comment, opposition accuses her justifying use of force in UT
- 'No legal action, FIRs being withdrawn': Bihar govt assures protesters in big win for students, CJP
- IndiGo's Delhi-Mumbai Airbus Makes Emergency Landing In Rajkot After Smoke Warning From Cargo Hold
- 47 GW battery storage, 23 GW pumped storage projects in pipeline
Hackers reportedly shared samples of the stolen data through Telegram chatbots with potential buyers. While Telegram took down the bots a day later, after initially labeling them as ‘Scam,’ hackers have previously used such bots to sell stolen data, including sensitive personal information from Indian citizens who signed up for the CoWIN portal.
Following the removal of the bots, hackers allegedly created a website where they offered the entire Star Health dataset for $150,000 (around Rs 1.25 crore).
The website’s message claimed, “I am leaking all Star Health India customers and insurance claims sensitive data. This leak is sponsored by Star Health and Allied Insurance Company, which sold this data to me directly. You can check the authenticity of the data in the Telegram bots below and read about how they sold it in the section below.”
Furthermore, the hackers accused Star Health’s Chief Information Security Officer ( CISO ) of selling them the data.
Star Health’s Response to the Allegations
In response to the breach, Star Health took legal action, filing a case against Telegram for allowing its platform to be used in selling stolen data. The company also filed a complaint against Cloudflare, accusing the US-based firm of hosting the hackers’ website.
However, Cloudflare has denied any involvement, stating that they did not host the domains in question.
Addressing claims about their CISO, Amarjeet Khanuja, Star Health said, “We also want to categorically mention that our CISO has been duly co-operating in the investigation, and we have not arrived at any finding of wrongdoing by him till date. We request that his privacy be respected as we know that the threat actor is trying to create panic.”





