India’s Star Health says it’s investigating after hacker posts stolen medical data

Date:

Share post:


Star Health and Allied Insurance, one of India’s biggest health insurance firms, is investigating a cybersecurity incident that allegedly leaked sensitive data associated with its customers, including their medical records.

The Chennai-headquartered insurance giant told TechCrunch that a “forensic investigation” is ongoing after data allegedly stolen from the company was shared online.

A hacker group recently created chatbots on Telegram to leak alleged personal data of Star Health’s policyholders, including their full names, phone numbers and home addresses, as well as medical reports and insurance claims. The data also appeared to include copies of ID cards and individuals’ tax details.

Reuters first reported the Telegram chatbots leaking the alleged Star Health customer data. Star Health says it has provided coverage to 170 million individuals to date.

The hacker group created a website to share the data with the links to the Telegram bots. The site, which TechCrunch has seen but is not linking to as it appears to contain sensitive personal information, also included a video allegedly showing screenshots and conversations between Star Health CISO Amarjeet Khanuja and the hacker group.

Star Health declined to comment when reached by TechCrunch with several questions about the incident.

“Given the circumstances, it would be premature for a listed entity to release a statement without completing a thorough investigation,” Star Health spokesperson Diana Monteiro said in an email.

Earlier on Thursday, Star Health said in a public notice in the Chennai edition of The Hindu newspaper, which TechCrunch has seen, that it was suing Telegram for hosting the chatbots. The insurer also named Cloudflare in its lawsuit for its role in hosting the hacker group’s website on its service.

As a result, the court issued interim injunctions to Telegram and Cloudflare to restrict them from allowing their platforms to be used by the hacker group to share Star Health’s branding in any form.

TechCrunch was able to verify that the hacker group’s website was inaccessible from certain internet providers in India, though the site was accessible from others at press time. Even when the website was blocked, it was redirecting to a web address hosted on a Cloudflare domain.

The insurer, which has more than 14,000 hospitals in its network and over 850 branch offices across India, has processed over $3.6 billion claims so far. It provides health, personal accident and overseas and travel insurance.

Telegram, Cloudflare, and India’s CERT-In did not respond to requests for comment.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Starlink hits 4 million subscribers

SpaceX’s Starlink satellite internet network is expected to hit a new customer milestone this week, company President...

OpenAI’s VP of global affairs claims o1 is ‘virtually perfect’ at correcting bias, but the data doesn’t quite back that up

Departures might be dominating the week’s OpenAI-related headlines. But comments on AI bias from Anna Makanju, the...

Former Brex COO who now heads unicorn fintech Figure says GPT is already upending the mortgage industry

Lending startup Figure announced today a rollout of AI tooling to make the home lending process more...

Nomi AI wants to make the most emotionally intelligent chatbots on the market

As OpenAI boasts about its o1 model’s increased thoughtfulness, a small, self-funded startup Nomi AI is building...

Zap Energy investors in recent $130M round included Soros Fund and Laurene Powell Jobs’ Emerson Collective

The race for commercial fusion power is heating up. Investors have poured money into fusion startups over the...

Kaspersky defends force-replacing its security software without users’ explicit consent

Earlier this week, some U.S. customers of Kaspersky’s antivirus were surprised to find out that the Russian-made...

The WordPress vs. WP Engine drama, explained

The world of WordPress, one of the most popular technologies for creating and hosting websites, is going...

Google’s NotebookLM enhances AI note-taking with YouTube, audio file sources, sharable audio discussions

Google on Thursday announced new updates to its AI note-taking and research assistant, NotebookLM, allowing users to...