India’s Star Health says it’s investigating after hacker posts stolen medical data

Date:

Share post:


Star Health and Allied Insurance, one of India’s biggest health insurance firms, is investigating a cybersecurity incident that allegedly leaked sensitive data associated with its customers, including their medical records.

The Chennai-headquartered insurance giant told TechCrunch that a “forensic investigation” is ongoing after data allegedly stolen from the company was shared online.

A hacker group recently created chatbots on Telegram to leak alleged personal data of Star Health’s policyholders, including their full names, phone numbers and home addresses, as well as medical reports and insurance claims. The data also appeared to include copies of ID cards and individuals’ tax details.

Reuters first reported the Telegram chatbots leaking the alleged Star Health customer data. Star Health says it has provided coverage to 170 million individuals to date.

The hacker group created a website to share the data with the links to the Telegram bots. The site, which TechCrunch has seen but is not linking to as it appears to contain sensitive personal information, also included a video allegedly showing screenshots and conversations between Star Health CISO Amarjeet Khanuja and the hacker group.

Star Health declined to comment when reached by TechCrunch with several questions about the incident.

“Given the circumstances, it would be premature for a listed entity to release a statement without completing a thorough investigation,” Star Health spokesperson Diana Monteiro said in an email.

Earlier on Thursday, Star Health said in a public notice in the Chennai edition of The Hindu newspaper, which TechCrunch has seen, that it was suing Telegram for hosting the chatbots. The insurer also named Cloudflare in its lawsuit for its role in hosting the hacker group’s website on its service.

As a result, the court issued interim injunctions to Telegram and Cloudflare to restrict them from allowing their platforms to be used by the hacker group to share Star Health’s branding in any form.

TechCrunch was able to verify that the hacker group’s website was inaccessible from certain internet providers in India, though the site was accessible from others at press time. Even when the website was blocked, it was redirecting to a web address hosted on a Cloudflare domain.

The insurer, which has more than 14,000 hospitals in its network and over 850 branch offices across India, has processed over $3.6 billion claims so far. It provides health, personal accident and overseas and travel insurance.

Telegram, Cloudflare, and India’s CERT-In did not respond to requests for comment.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

HPE investigating security breach after hacker claims theft of sensitive data

Hewlett-Packard Enterprise is investigating a data breach after a well-known hacker claimed to have stolen sensitive information...

MoneyHash, which provides single access to payment services in MENA, banks $5.2M

When merchants or companies launch online, they typically start by partnering with one or two payment processors....

Karmen secures $9.4 million for its revenue-based financing products

French startup Karmen has secured a small funding round so that it can improve its instant financing...

President Trump signs exec order to make Musk’s DOGE commission more official

The Department of Government Efficiency (DOGE), an advisory commission spearheaded by billionaire Elon Musk recommending deep cuts...

Trump signs exec order delaying TikTok enforcement action for 75 days

President Donald Trump has signed an executive order aimed at restoring TikTok service in the U.S. The order...

President Trump repeals Biden’s AI executive order

During his first day in office, President Donald Trump revoked a 2023 executive order signed by former...

UK to unveil ‘Humphrey’ assistant for civil servants with other AI plans to cut bureaucracy

A week after the U.K. government announced a sweeping plan to make big investments into AI, it’s...

OpenAI’s agent tool may be nearing release

OpenAI may be close to releasing an AI tool that can take control of your PC and...