Health-Tech Company Moves Supreme Court Seeking CBI Probe Into Cyber Attack & Data Theft
The Supreme Court today issued notice on a petition seeking a CBI/Court-monitored SIT probe into the alleged hacking and theft of citizens' personal and medical data stored at a health-tech company.
A bench of CJI Surya Kant, Justice Joymalya Bagchi and Justice V Mohana passed the order on the plea of one Vitraya Technologies Pvt. Limited, which has a digital platform for real-time settlement of health insurance claims. Senior Advocate K Parameshwar appeared for the petitioner.
He submitted that the data breaches happened across six States. "I have been informing the authorities from day one. I filed my complaint in March 2025. It took them till August 2025 even to register an FIR," he submitted. He added that the FIR invoked only Section 66 of the Information Technology Act, which was inadequate. "I gave them the details of the Singapore server where the medical records of nearly 1.5 lakh Indian citizens have gone. Even today, the FIR is against unknown persons. How do I trust this investigation?," he submitted.
The company states that its competitors/entities associated with them attacked its servers in an attempt to steal data. Only after great efforts, an FIR was registered however no fruitful action has been taken by the agency. Doubting the impartiality of the authorities, the petitioner seeks a specialized probe by CBI or an SIT.
On the strength of Article 21 rights, the petition highlights that the issues concern the confidential data and privacy of citizens. It states that there is a risk of unauthorized access of highly confidential data of people, including Aadhaar-linked information, insurance claims and medical records.
According to the averments, a sophisticated cyber intrusion was identified in February 2025, which involved brute-force login attempts, mass downloading of confidential records and extraction of sensitive customer data from the petitioner's infrastructure. Upon an internal probe, the petitioner traced the suspicious activities to entities owned by a foreign fund called M/s Bessemer Venture Partners, which allegedly coordinated the attacks with the petitioner's competitors.
It is stated that in March 2025 itself, the police authorities were given technical logs, server data, IP details, names of persons involved, and supporting material, in a complaint. However, the authorities failed to register the FIR for 6 months. Ultimately, an FIR was registered, but only under Sections 66 and 66B of the IT Act, that too, against 'unknown persons'.
"the investigating agency has failed to undertake any meaningful, diligent or effective investigative measures in relation to the aforesaid FIR and appears to be proceeding with complete inaction in the matter despite follow ups and representations made by the Petitioner. Such continued inaction assumes greater significance considering the grave nature of the allegations involving nationwide data privacy concerns and the potential compromise of sensitive personal information of ordinary citizens", the plea states.
The petition has been filed through AoR Abhinav Agrawal.
Case Title: VITRAYA TECHNOLOGIES PVT. LTD Versus UNION OF INDIA AND ORS. Diary No. 31408-2026