Star Health Data Breach: Supreme Court Refuses To Quash Criminal Case Against Cybersecurity Expert
Kirit Singhania
5 Oct 2026 2:12 PM IST

The Supreme Court on Monday refused to interfere with criminal proceedings against cybersecurity researcher Himanshu Pathak on a complaint filed by Star Health and Allied Insurance Company over alleged unauthorised access to and downloading of sensitive customer data.
The Court had on August 6 directed Pathak to appear before the XI Metropolitan Magistrate, Chennai and furnish bail bonds while hearing his challenge against a Madras High Court judgment which declined to quash the criminal proceedings arising from Star Health's complaint.
Pathak claims that he had discovered critical vulnerabilities in Star Health's systems and reported them to the company and cybersecurity platform certain, seeking their rectification. Star Health alleges that Pathak unauthorisedly accessed and downloaded around 8,000 files containing customers' personal, health and financial information and subsequently attempted to pressure the company by threatening publication of information unless it engaged his cybersecurity services.
A Bench of Chief Justice Surya Kant, Justices Joymalya Bagchi and V. Mohana after hearing both the parties, refused to interfere with the criminal proceedings.
Appearing for Pathak, Advocate Prashant Bhushan submitted that Star Health had described his client as a “habitual offender” in its counter-affidavit by referring to another FIR registered against him on a complaint by Policybazaar.com concerning similar allegations.
Bhushan pointed out that Star Health had not disclosed that the Policybazaar case had subsequently been closed by the police.
He referred to the closure report placed in Pathak's rejoinder, which recorded that the investigation had found that Pathak had provided information to the complainant company regarding critical vulnerabilities and leakage of sensitive and confidential user data and documents relating to customers' personal, health and financial information.
Bhushan submitted that the Policybazaar case was therefore significant because the allegations had already been investigated by the police and had resulted in a closure report.
He argued that Pathak's entire exercise was bona fide and that there was no intention to misuse the data or extort Star Health.
“The entire exercise was most bona fide. There was no intention, in fact, the proposal for business. Otherwise, we wouldn't have reported it to certain and to the company itself,” Bhushan submitted.
The Bench however, indicated that whether Pathak's conduct was bona fide was ultimately a matter involving an assessment of the evidence.
The Bench observed that Pathak's defence would have to be weighed against the allegations made against him and questioned whether such factual issues could appropriately be determined while exercising jurisdiction under Section 482 CrPC.
Bhushan responded that his complaint was precisely that the High Court had failed to examine the material relied upon by the defence while refusing to interfere with the prosecution.
He submitted that the High Court, while exercising jurisdiction under Section 482, could examine whether the prosecution itself was mala fide and whether the materials disclosed an offence.
Bhushan further pointed out that Pathak had previously reported vulnerabilities to several organisations, including Punjab National Bank, Vodafone and CDSL.
He submitted that those organisations had acknowledged the vulnerabilities and taken steps to address them, demonstrating that Pathak's conduct was consistent with that of a cybersecurity researcher identifying vulnerabilities.
“The Punjab National Bank thanked us and said that we have shut down this thing and we are now fixing it. CDSL also said the same thing. Vodafone also said the same thing, because we identified that there is a critical breach in your whole system by which anybody can access it,” he argued.
Bhushan said cybersecurity researchers routinely identify vulnerabilities and report them to affected organisations.
“We have never published anybody's data. Never put someone's data out. A good Samaritan going to everybody else's website to see there is a vulnerability. That's our job, my Lord. Cybersecurity experts, we do this job,” he submitted.
The Bench, however, questioned the limits of such conduct and pointed out that a cybersecurity researcher cannot simply access another person's system or data without authorisation.
The Court observed that downloading the data was a particularly serious aspect of the allegations.
The Bench questioned why Pathak had downloaded the data once he had identified the vulnerability and whether it was necessary to remove the data from the company's system to establish the existence of the security flaw.
Bhushan responded that merely demonstrating access would not necessarily establish the extent of the vulnerability and that the downloaded material was used to demonstrate the problem to the company.
He maintained that Pathak had not published the data or supplied it to unauthorised persons.
“I didn't publish it. I didn't send it to any unauthorised person. I only sent it...” Bhushan submitted.
The Bench however, emphasised that the moment sensitive personal information is removed from a company's database, the privacy interests of the individuals whose information is contained in that data are implicated.
The Court also drew a distinction between merely informing a company that its system was vulnerable and actually downloading thousands of files containing customers' personal information.
Star Health represented by Senior Advocate S. Muralidhar, relied on the contents of Pathak's communications with the company. Muralidhar referred the Bench to an email at the bottom of page 26 of the paper book and submitted that it demonstrated that the communications went beyond a simple vulnerability disclosure.
The email stated that the researchers were hoping for a “swift fix” of the critical security issues and referred to plans to publish articles about the issues through reputed publications nationally and internationally.
It further stated that they would not publish anything until the issues were fixed and requested a timeline from Star Health for rectification.
Muralidhar characterised the communication as an implied threat.
“This is not an ordinary person you're dealing with,” he submitted while referring to the email and the subsequent communications.
He argued that the sequence of the communications had to be examined carefully, particularly because the initial email preceded Pathak's proposal to provide cybersecurity assistance to Star Health.
The Bench also examined the email and noted that it contained a reference to publishing the security issues through reputed publications.
Muralidhar submitted that the relevant question was not merely whether Pathak had ultimately published the data, but whether he had unlawfully obtained and retained sensitive customer information and then used the existence of that information to exert pressure on the company.
He drew an analogy to a person obtaining damaging private information about someone and threatening to disclose it unless the person changed their conduct.
The Bench observed that even if a person believed that another entity was acting improperly, that did not necessarily authorise the person to obtain private information and use its possession as leverage.
Muralidhar also relied on the fact that Pathak had downloaded approximately 8,000 files.
Muralidhar submitted that once the information had been downloaded, the issue was no longer confined to vulnerability testing but involved the protection of individual customers' privacy.
The Bench also questioned how the company could establish the precise nature and volume of information accessed.
Muralidhar responded that the company's systems maintained records and metadata showing which files had been accessed, thereby making the issue capable of being examined during the trial.
He further referred to communications in which Pathak allegedly demanded USD 65,000 for an attack-surface analysis and USD 3,000 per month for maintenance.
Muralidhar submitted that the communications concerning payment, when considered alongside the alleged downloading of thousands of files and the references to publication, supported the prosecution's case and could not simply be brushed aside at the threshold.
Bhushan however, disputed the characterisation of the communications as extortion.
He submitted that the chronology showed that Pathak had first identified the vulnerability, informed Star Health and sought its rectification. According to him, only subsequently did the company discuss obtaining Pathak's professional assistance in fixing the vulnerability.
He argued that Pathak's demand for professional remuneration for providing cybersecurity services could not be equated with a threat to disclose customer information.
“In fact, from the conversation, it is clear that they sought my help to try and fix that data. And thereafter, they also sought my help, saying that we want to engage you as a long-term consultant for us to help us with our security system,” Bhushan submitted.
He said that Pathak had consistently told the company that his primary objective was to have the vulnerability fixed.
“I kept telling them that, look, I am only interested that you should fix your system,” he submitted.
According to Bhushan, when Star Health subsequently sought to engage Pathak as a consultant, he merely communicated his professional fee.
“At that point I said, all right, if you want to engage us for this, this is my fee for doing this work. That's all. How can I be blamed for doing something, not as a good Samaritan?” he argued.
Bhushan also strongly disputed Star Health's characterisation of the first email as a threat to publish customer data.
He submitted that the communication was a warning that the existence of the vulnerability could be publicly reported so that customers became aware of the security issue, and not a threat to publish the personal information itself.
Bhushan also sought to distinguish Pathak's case from the examples cited by Star Health, maintaining that he had never published the personal data of any organisation whose systems he had examined.
The Bench, however, questioned whether a person could independently access and download data merely because the objective was to demonstrate a vulnerability.
The Court also questioned whether a cybersecurity expert was permitted to enter another person's system without authorisation and access information merely because the expert intended to report a vulnerability.
Bhushan maintained that Pathak's conduct had to be assessed in the context of responsible disclosure and the absence of any allegation that he had sold or disseminated the downloaded data.
The Court observed that these competing versions raised factual questions concerning the circumstances in which the data was accessed, why it was downloaded, what was subsequently done with it and what was communicated to Star Health.
Bhushan ultimately requested the Supreme Court to direct the High Court to examine the issues raised by the defence, contending that the High Court had not adequately considered the material demonstrating that the prosecution was allegedly mala fide.
After hearing the rival submissions, the Supreme Court declined to interfere with the criminal proceedings, leaving the competing allegations and Pathak's defence to be examined in accordance with law before the trial court.
