Skip to content
Back to Blog
·10 min read·news

Star Health Data Breach: What Indian Insurers Must Learn

The Star Health data breach exposed sensitive customer data via Telegram bots. Learn the data minimisation and access-control lessons Indian insurers need.

BR

Bachao.AI Research Team

Cybersecurity Research

Get Your Free VAPT Scan

Business impact of this development

Emerging threats move fast. Indian SMBs are primary targets because they're under-defended. Here's what you need to know and do now.

The Star Health data breach surfaced in September 2024 when a threat actor using the alias "xenZen" began distributing sample customer records through Telegram chatbots, then offered the full dataset for sale on a hacker forum. Reporting from Reuters and TechCrunch, based on files researchers and journalists reviewed directly, described data tied to millions of Star Health customers, including names, contact details, policy and claims records, medical reports, and ID documents. Star Health disputed the scope of the compromise while suing Telegram and Cloudflare in the Madras High Court. For any Indian insurer holding health, financial, and identity data at scale, the case is a concrete lesson in what happens when data minimisation, access control, and breach disclosure are treated as paperwork instead of engineering.

What Happened in the Star Health Data Breach

Star Health and Allied Insurance Company, India's largest standalone health insurer, was first linked to the leak in September 2024 after UK-based security researcher Jason Parker discovered two Telegram chatbots offering customer data for download. Parker reported that a user operating under the alias "xenZen" claimed to hold 7.24 terabytes of data tied to more than 31 million Star Health customers and over 5.8 million insurance claims, and was offering the full dataset for a reported $150,000.

Reuters tested the bots directly and downloaded more than 1,500 files, some dated as recently as July 2024, describing the material as including full names, phone numbers, home addresses, medical reports, insurance claims, ID card copies, and tax details. Star Health's public position stayed narrower throughout — the company said it was investigating and did not confirm the scale independent researchers and journalists described.

ℹ️
INFO
Star Health has consistently disputed the full extent of the breach described by researchers and journalists, saying no widespread compromise of its core systems was found. Where the company's statements and third-party reporting diverge, this article states each position separately rather than treating either as fully settled.

What made this incident unusual was the distribution mechanism, not just the data itself. Instead of a static forum listing, xenZen built Telegram bots that let anyone query and download sample records on demand, with the bulk dataset held back for a paying buyer — a self-service model for stolen medical data, running on a mainstream app rather than requiring a Tor browser or forum credentials.

graph TD A[Customer Data Exposed] -->|Samples shared| B[Leaked via Telegram Bots] B -->|Dataset advertised| C[Extortion and Sale] C -->|Company response| D[Legal Action Filed] D -->|Post-incident review| E[Lessons for Insurers] style A fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style B fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style C fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style D fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style E fill:#1e3d2f,stroke:#10B981,color:#e2e8f0

Telegram told Reuters it removed the two original bots within 24 hours of being notified, but new bots distributing the same data kept appearing. Telegram later said it swept a large share of related content off the platform, though the pattern shows how quickly a bot-driven leak can outpace platform-level takedowns.

What Data Was Reportedly Exposed

Public reporting — sourced to Reuters' direct testing of the chatbots and Jason Parker's research — described the leaked material as spanning several categories of sensitive personal and health information. Star Health has not published its own confirmed inventory of what was exposed, so the breakdown below reflects categories journalists and researchers said they observed in downloaded samples, not a verified company disclosure.

pie title Data Types Reported in Leaked Samples "Policy and Claims Records" : 35 "Medical Reports" : 25 "Identity Documents" : 20 "Contact Details" : 20
⚠️
WARNING
Medical diagnosis data combined with identity documents and policy numbers is a materially higher-risk exposure than a typical contact-details leak. It enables targeted fraud, insurance-linked phishing, and in the worst cases health-condition-based discrimination or blackmail.

A separate, contested claim added to the story: xenZen alleged collusion with Star Health's own Chief Information Security Officer to obtain access, posting screenshots that were never independently verified at the time. Star Health publicly backed its CISO and denied the allegation, and later reported that a forensic investigation it commissioned found the alleged CISO communications had been fabricated, with no evidence linking him to the breach. Whether or not every detail of that resolution is independently auditable, the episode points to a control question every data holder should ask directly: how tightly is privileged access to bulk customer data actually monitored and logged, independent of who holds the credentials.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

Star Health filed a complaint in the Madras High Court against Telegram for hosting the chatbots, and separately named Cloudflare for hosting websites used by the hacker group. The court granted a temporary injunction ordering both platforms to block access to the compromised data and restrict use of the Star Health name. In later hearings, the court directed Star Health to share specific chatbot and URL details so Telegram could act — Telegram's counsel argued it could not proactively search for and remove leaks at scale, only respond to specific reports.

7.24 TBData volume the hacker claimed to hold (Reuters and TechCrunch reporting, Sept 2024)
31 millionCustomers researchers said were affected in downloaded samples (Reuters, TechCrunch, Sept 2024)

The litigation illustrates a hard truth for any Indian company relying on legal remedies after a leak: a court order compelling one platform to remove specific bots does not retroactively contain data already copied, resold, or mirrored elsewhere. By the time flagged usernames work through a legal process, the underlying dataset has typically changed hands. Legal action can punish the platform and the actor after the fact — it does not undo the exposure.

Table: Control Gaps This Incident Highlights vs What Insurers Should Verify

Risk AreaWhat Was ReportedWhat to Verify Internally
Data minimisationMulti-terabyte dataset spanning years of claims and medical records reportedly accessibleAre historical records retained longer, or in more detail, than the business function needs?
Access controlsBulk customer data reportedly retrievable through a small number of access pathsIs access to sensitive records segmented by role, with logging on every bulk query?
Third-party/platform riskLeak distributed through a consumer messaging platform outside the insurer's controlDo you monitor for your organisation's data appearing on external platforms?
Breach disclosurePublic company statements and independent reporting diverged on scaleDoes your incident response plan define what gets disclosed, when, and to whom?
Privileged access monitoringDisputed insider-collusion claim drew scrutiny to internal access controlsIs privileged access to bulk datasets monitored as closely as external-facing systems?
💡
TIP
A free VAPT scan surfaces externally reachable APIs and endpoints capable of bulk data retrieval before an attacker finds them — the same class of weakness bot-driven leaks like this one tend to exploit.

Why This Matters Under India's DPDP Act

The Digital Personal Data Protection (DPDP) Act 2023 makes an incident like this a direct compliance event, not just a reputational one. Health and financial data of the kind Star Health holds sits inside the categories the Act is built to protect, and obligations run in both directions — implementing reasonable security safeguards beforehand, and notifying the Data Protection Board and affected individuals correctly once a breach occurs.

250 crore rupeesMaximum DPDP Act penalty for failure to implement reasonable security safeguards (MeitY, Digital Personal Data Protection Act 2023)
6 hoursCERT-In mandated window to report specified cyber incidents after detection (CERT-In Cyber Security Directions 2022)
🛡️
SECURITY
Under the CERT-In Cyber Security Directions of 2022, entities covered must report specified categories of cyber incidents to CERT-In within six hours of detection — far tighter than most internal escalation processes are built for. Large processors of sensitive data, such as a national health insurer, also carry additional obligations as significant data fiduciaries, including audits and data protection impact assessments.
🎯Key Takeaway
The most damaging part of a breach like Star Health's is rarely the initial intrusion — it is how much sensitive data was sitting in retrievable, bulk-accessible form once an attacker found a way in, and how quickly and accurately the company's public response matched what actually happened. Data minimisation, tight and logged access control, and honest early disclosure are cheaper than any of the alternatives.

What Indian Insurers Should Do Differently

First, inventory where health and financial data actually lives — including logs, backups, and third-party integrations — because minimisation only works once the full footprint is known. Historical claims documents and medical reports retained indefinitely in easily queryable form are exactly the kind of asset that turns a single compromised credential into a multi-terabyte leak.

Second, put query-level rate limiting and anomaly detection on any internal system or API capable of returning bulk customer records; a single account retrieving thousands of records in a short window should trigger an alert, not just sit in a log. Third, run breach-notification drills, not just breach-response drills — knowing what to disclose, to whom, and within what window under CERT-In's six-hour rule and the DPDP Act is a distinct skill from technical containment, and the gap between Star Health's early statements and later reporting shows how costly that distinction can be.

🚨
DANGER
Insurers that store scanned medical reports, diagnosis codes, or claims documentation in the same access tier as routine policy metadata are creating unnecessary blast radius. Segment by sensitivity, not just by system.

Fourth, treat platform and third-party exposure as part of the attack surface. Data need not leave an organisation's own systems to become a breach — a compromised integration or over-permissioned partner API can produce the same outcome, and containment then depends on cooperation from platforms the organisation does not control. Regular external testing, cycled with a CERT-In empanelled partner for regulatory engagements, should cover the data-access layer, not just perimeter ports.

Bachao.AI, built by Dhisattva AI Pvt Ltd, runs continuous automated VAPT designed to close exactly these gaps — mapping external attack surface, testing access controls on data-handling systems, and producing the kind of audit trail regulators and boards now expect after incidents like this one. Insurers evaluating their own DPDP readiness should start with a structured technical and process-level review rather than a generic policy checklist — see DPDP compliance guidance for what that actually covers.

Conclusion

The exact scope of the Star Health breach remains disputed, but the pattern from public reporting is clear: sensitive health and financial data, once accessible in bulk, found a low-friction distribution channel faster than legal remedies or public statements could keep pace with. For Indian insurers, and any business holding comparable data, the lesson is a discipline, not a single control — minimise what you retain, restrict and log who can query it in bulk, and rehearse disclosure before an incident forces you to improvise it.

Frequently Asked Questions

Frequently Asked Questions

What actually happened in the Star Health data breach?
In September 2024, a threat actor using the alias "xenZen" ran Telegram chatbots distributing sample Star Health customer records and offered a larger dataset, reported at 7.24 terabytes, for sale. Reuters and TechCrunch reported the samples included policy, claims, medical, and identity data; Star Health disputed the full scale while suing Telegram and Cloudflare in the Madras High Court.
How many Star Health customers were affected?
Independent researchers and journalists, including Reuters and TechCrunch based on Jason Parker's research, reported data tied to more than 31 million customers and 5.8 million insurance claims. Star Health did not confirm this figure and maintained it found no widespread compromise of its core systems, so the exact scope remains disputed.
What legal action did Star Health take?
Star Health filed a complaint in the Madras High Court against Telegram, for hosting the leak-distributing chatbots, and separately named Cloudflare for hosting the hacker's websites, along with the hacker directly. The court granted a temporary injunction ordering both platforms to block access to the compromised data.
Was there an insider involved?
The hacker claimed to have colluded with Star Health's Chief Information Security Officer to obtain the data, posting screenshots as evidence. Star Health publicly backed its CISO and denied the allegation, and the company later said a forensic investigation it commissioned found the alleged communications were fabricated and no evidence tied the CISO to the breach.
What does the DPDP Act require insurers to do after a breach like this?
The Digital Personal Data Protection Act 2023 requires data fiduciaries to implement reasonable security safeguards and to notify the Data Protection Board and affected individuals of a personal data breach. Entities covered by CERT-In's directions must also report qualifying cyber incidents to CERT-In within six hours of detection.
How can an insurer check if it has similar exposure?
Start with a technical audit of externally reachable APIs and internal systems that can return customer records in bulk, paired with a DPDP-focused compliance review. A free VAPT scan and DPDP compliance guidance are practical starting points.

Sources: CERT-In Cyber Security Directions 2022 · Digital Personal Data Protection Act 2023, Ministry of Electronics and Information Technology

Explore more verified incident breakdowns and compliance guidance on the Bachao.AI blog.

BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Find the gaps attackers use for initial access — before they do

Free automated scan — risk score in under 2 hours. No credit card required.

Get Your Free VAPT Scan
Find your vulnerabilitiesStart free scan →