Desk live·
ForensicPost
Breaches/Concentration/File 24-0920

Star Health Lost Customer Diagnoses and Test Results to Messaging Bots

India’s largest health insurer lost customer records including diagnoses and test results. The data was distributed through automated bots on a messaging platform.

Constructed geometry · not a chart of case data
JurisdictionIndiaChennaithe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetStar Health and Allied Insurance
ActorUnattributed
D. Kennedy13 min readConfidence: medium3 sources reviewed

In September 2024 records belonging to Star Health and Allied Insurance were found being distributed through chat bots on Telegram. Reporting put the affected population above 31 million customers.

The material was described as including names, telephone numbers, addresses, tax identifiers, copies of identity documents, medical diagnoses and test results. It was surfaced by a researcher who alerted news agencies.

The Distribution Method Is The New Part

A leak site is a shop window: it advertises, and a buyer has to make contact. A chat bot is a vending machine. Anybody with the messaging app can query it and receive records about a named individual, with no negotiation and no gatekeeper.

That lowers the effort of misuse from "acquire a database and process it" to "look somebody up". For an insurance file containing diagnoses, that difference is the whole of the harm.

Medical Data Does Not Expire

The corpus recorded at 26-0324 that some categories cannot be reissued. A card is replaced, a password is rotated; a diagnosis is permanent and so is its capacity to affect employment, relationships and standing.

Credit monitoring, the standard remedy across this database, does nothing for any of that. It is a control designed for financial fraud offered for a harm that is not financial.

And It Is A File This Corpus Would Normally Miss

Indian incidents are under-represented here for the reasons set out at 25-0502: the routes by which an incident becomes public — a disclosure obligation, collective redress, English-language publication — favour a handful of jurisdictions.

This one surfaced because a researcher found it and international agencies picked it up, which is not a mechanism and cannot be relied on. Graded medium: the scale and content are as reported and this desk has seen no completed regulatory finding.

How we reported this

Compiled from contemporaneous reporting, listed below. The 31 million figure and the description of the data types are as reported; this desk has not seen a company or regulatory confirmation of the scope and has not examined any sample. Graded medium. The allegations circulated about an individual employee are dealt with separately at 24-1010 and are not repeated here. Corrections: corrections@forensicpost.com.

Sources
  1. Star Health data breach affects 31 million usersMediaNama
  2. Star Health breachThe Register
  3. Star Health investigates massive data breachBusiness Today
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary