Star Health Data Leak: 3 Cr Customers Affected, CISO Allegedly Involved

By By Rediff Money Desk, New Delhi
Oct 09, 2024 21:46
A hacker claims to have obtained personal data of 3.1 crore Star Health customers, alleging the company's CISO sold the data. Star Health is investigating.
Illustration: Uttam Ghosh/Rediff.com
New Delhi, Oct 9 (PTI) Personal data like mobile numbers, PAN, addresses and pre-existing medical conditions of about 3.1 crore customers of Star Health Insurance is allegedly available on a website created by a hacker identified as xenZen.

The hacker claimed that Star Health's Chief Information Security Officer (CISO) sold all the data and later tried to change the terms of their deal.

According to the details shared by the UK-based researcher Jason Parker on September 20, a hacker by the name of xenZen has published a website with sample data of Star Health Insurance Company and an email communication with a top official responsible for handling and managing the digital network of the company.

"I am leaking all Star Health India customers and insurance claims sensitive data. This leak is sponsored by Star Health and Allied Insurance Company, who sold this data to me directly," xenZen claimed.

Clarifying on the matter Star Health Insurance in a statement said, a thorough and rigorous forensic investigation, led by independent cybersecurity experts is underway, and the company is working closely with government and regulatory authorities at every stage of this investigation.

"We also timely approached the Madras High Court which in the attached order has directed all including certain third parties to disable access to the relevant information. We are diligently pursuing the implementation of this order," it said.

The company categorically mentioned that the CISO has been duly co-operating in the investigation and has not arrived at any finding of wrongdoing by him till date.

"We also want to emphasize that any unauthorised acquisition, possession, or dissemination of customer data is illegal. We urge all platforms, hosting companies, social media channels and users to take swift and decisive action to halt such activities and comply with the orders of the High Court," it said.

Meanwhile, Madras High Court has observed that protection is vital to prevent the continuous leakage of such sensitive data and referred the matter for further hearing on October 25.

The hacker has created Telegram bots to access data of 31,216,953 customers updated till July 2024 and 5,758,425 claims of the company available till early August.

The email conversation video showed the email ID of the senior company official. The conversation video shows email chat as well as a chat on an instant messaging forum between xenZen and the company official for the deal.

The deal was initially finalised for USD 28,000 but later the official demanded USD 150,000 on the pretext that he has to pay a share to senior-level management for continuation of the data leak, the hecker alleged.

Any leak of personal details of people makes them vulnerable to online scams.
Source: PTI
Read More On:
cybersecuritydata breachpersonal datadata leakstar health
DISCLAIMER - This article is from a syndicated feed. The original source is responsible for accuracy, views & content ownership. Views expressed may not reflect those of rediff.com India Limited.

You May Like To Read

MORE NEWS

TVS Tech Centre Opens in Assam

TVS Credit tech centre inaugurated in Assam by CM Sarma. Centre to train youth in AI,...

Shiprocket Files IPO Papers; Eyes ₹2,342 Cr...

Shiprocket files updated IPO papers with Sebi, aiming to raise ₹2,342 cr via public...

SAIL Sales Up 14% in Apr-Nov Amid Price Pressures

SAIL reports 14% sales growth to 12.7 MT in Apr-Nov 2025 despite price pressures and...

Chennai Bullion Rates Today

Check the opening bullion rates in Chennai today. Gold (22K, 18K) and silver prices per...

NAFED Urad Procurement in UP: 50 Centers Open

NAFED to open 50 urad procurement centers in 17 UP districts. Farmers can sell at MSP...

NCLAT Asks Renewal of Bank Guarantee for IL&FS...

NCLAT directs Brookfield-backed Chronos to renew bank guarantee for acquiring IL&FS...

SBI Reduces Lending Rate After RBI Cut

SBI cuts lending rate by 25 bps after RBI rate cut. Loans become cheaper for borrowers....

Pakistan & Binance Pact: Tokenisation of Assets

Pakistan and Binance sign MoU for tokenisation of assets up to USD 2 billion. Boost...

IndiGo Seeks Rs 900 Cr Customs Duty Refund in...

IndiGo moves Delhi HC for Rs 900 crore Customs duty refund on re-imported aircraft...

Sebi Clears Pranav Adani in Insider Trading Case

Sebi clears Pranav Adani, Adani Group director, of insider trading charges related to...

Read More »

Sectoral Indices Market Indicators Listed Companies Gainers Losers Mutual Funds Portfolio Watchlist
© 2025 Rediff.com