Supreme Court Urges Star Health Insurance To Withdraw Case Against Cyber Expert Who Exposed Vulnerability In System
"What did you fix? Do you know the value of individual data on dark web?" Justice Bagchi questioned Star Health's lapse.
In an attempt to put a quietus to the dispute, the Supreme Court today told Star Health and Allied Insurance Company to withdraw its case against cybersecurity expert Himanshu Pathak who allegedly "hacked" into the company's data to expose vulnerabilities.
A bench of CJI Surya Kant, Justice Joymalya Bagchi and Justice V Mohana called on Advocates S Shivathanu Mohan and Shloka Narayanan, the Star Health counsels, to obtain instructions, saying, "whatever it may be...you are not facing a class action over vulnerability. Take instructions whether you can put a quietus to it".
Justice Bagchi, in particular, noted that no harm had been caused to Star Health due to the petitioner's conduct. Rather, owing to the same, it had perhaps come out wiser. "At the end of the day, no harm has been caused to you. Maybe that this information, and the anxiety to make money out of that information, has really put you on the right track, and you became wiser than what you have been in the past", the judge expressed.
Questioning Star Health over its claim of having "fixed" the problem, Justice Bagchi noted that the Company told CERT-IN that it had fixed the problem, yet within a year, a cyber attack happened. "What did you fix? Do you know the value of individual data on dark web?" the judge remarked.
While calling on Star Health to put a quietus to the issues, the bench also said that it will take an undertaking from the petitioner that he will have nothing to do in future with the company's data.
Briefly put, the petitioner initially approached the High Court seeking directions to the Union, the IRDAI and the SEBI to inquire into alleged data security lapses at Star Health. In a representation to Union Ministries, he had claimed that there were vulnerabilities in the Company which could expose consumer data to third party.
In 2024, while the petitioner's plea was pending before the High Court, the Company came under a cyber attack. The petitioner claimed that though the Company initially thanked him for flagging the vulnerability, it later filed a case against him for unauthorized access and stealing data.
Star Health, on the other hand, claimed that the petitioner hacked into the Company's data and threatened it to avail his services. As such, an FIR was lodged against him. In the said case, chargesheet had been filed and the petitioner's plea to quash the case got dismissed.
After the High Court's rejection of his plea, the petitioner approached the Supreme Court. Appearing on his behalf, Advocate Prashant Bhushan contended that Star Health was trying to sell customer data to unauthorized persons for a "huge sum of money". Despite the petitioner's complaint, the company did not act and in 2024, it came under cyber attack.
In response to a Court observation, the counsel emphasized that the petitioner did not "hack" into the company's data. Even though his report to the company was voluntary, he was not playing a marketing tactic, else he would not have gone to IRDAI or SEBI, Bhushan argued.
He further highlighted that CERT-IN accepted the Company's claim that the issue had been resolved, but later a cyber attack took place.
Hearing the submissions, CJI Kant questioned the petitioner's conduct of accessing data of policyholders other than his father. The CJI exclaimed that the petitioner could not "target" a public health insurance company like that while "sitting in his office". "You can enter anybody's privacy? You were indulging in bargain", said the CJI.
Bhushan defended the petitioner's action, saying he was obligated to report the lapse to authorities. The counsel further pressed that it was matter of data of 31 million people, whose photographs from hospitals were exposed to third-party access.
Justice Bagchi however questioned the petitioner's motives, remarking that he wished to exploit the company's vulnerability as a marketplace. He added that the Court would direct the regulatory authorities to take appropriate steps.
Justice Mohana, on the other hand, noted that civil and criminal cases were already underway and a penalty of Rs.3.5 crores (approx.) had already been imposed.
Star Health maintained that the petitioner's breach of its data was pre-planned and that he threatened to publish it. "He had been studying my system for 5 months," the Company's counsels submitted. The matter was adjourned to enable the Star Health counsels to obtain appropriate instructions.
Background
The petition has been filed by cybersecurity expert Himanshu Pathak, proprietor of CyberX9, against the Madras High Court's judgment dismissing his plea seeking directions against Star Health and Allied Insurance Company over alleged cybersecurity vulnerabilities that put customers' personal data at risk.
Pathak claims that while accessing his insurance policy, he discovered vulnerabilities that could expose the personal data of other policyholders. When he informed the insurer, civil and criminal proceedings were initiated against him over allegations of unauthorized access to the company's systems.
His petition seeking action was dismissed by a Single Judge on October 23, 2024 where it was held that the dispute over the alleged data breach and vulnerabilities was already sub judice in pending civil proceedings. Although, the Judge granted him liberty to pursue remedies after the suit's conclusion.
Thereafter, Pathak's intra court appeal was dismissed, noting that he had neither established any breach of his own personal data nor infringement of any personal right. The High Court held that Computer Emergency Response Team and other authorities had already been informed of the incident and that the insurer had taken corrective measures.
Case Title: HIMANSHU PATHAK Versus MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY AND ORS.