Star Health Insurance Sues Telegram Over Data Leak by Hacker Using Chatbots

SUMMARY

  • Star Health Insurance has sued Telegram and a hacker after policyholder data was leaked through chatbots on the platform.
  • The Madras High Court issued a temporary injunction ordering the removal of chatbots distributing the data and blocking associated websites.
  • The lawsuit also includes U.S.-based Cloudflare, accused of hosting websites with leaked data, with a hearing set for October 25.

Star Health Insurance, one of India’s largest insurers, has initiated legal action against messaging platform Telegram and a self-styled hacker after personal and medical data of its policyholders were leaked through chatbots on the app. This lawsuit follows a Reuters report that revealed the hacker had been leaking confidential data, including medical reports, using Telegram’s bot features.

The Madras High Court in Tamil Nadu granted Star Health a temporary injunction, compelling Telegram and the hacker to block any chatbots or websites distributing this sensitive information. Additionally, the insurer has sued Cloudflare, a U.S.-based software firm, accusing it of hosting the leaked data on its services.

In the court filing, Star Health emphasized that the hacker accessed and leaked confidential customer information through Telegram’s platform. The court has issued notices to both Telegram and Cloudflare, with a hearing scheduled for October 25. The insurer has also demanded that Telegram and Cloudflare refrain from using the trade name “Star Health” or sharing its data online.

Star Health, which has a market capitalization exceeding $4 billion, made the lawsuit public through an advertisement in The Hindu newspaper. While Telegram and Cloudflare did not respond to the requests for comment, Telegram has been under growing scrutiny globally, especially after the arrest of its founder Pavel Durov in France for alleged facilitation of illegal activities through the app. Both Telegram and Durov have denied any wrongdoing.

The lawsuit comes as hackers increasingly use chatbots to disseminate stolen data. Reuters reported that the hacker, identified as xenZen, was able to make stolen data from Star Health accessible on Telegram, offering claim documents and personal details of policyholders. In response to the exposure, Telegram removed the chatbots within 24 hours, but new ones appeared shortly after. The leaked documents, some as recent as July 2024, included sensitive information such as policy numbers, personal identification details, and medical diagnoses.

Star Health had earlier stated that there was “no widespread compromise” detected, and sensitive customer data remains secure. However, the court’s action aims to prevent further leaks and hold responsible parties accountable for the breach.