← Case Files · The Breach Files

2024 · Health insurance (India)

Star Health, 2024: a data leak with a customer service bot

Case file · 5 min read · Published 15 September 2026

People affected
Claims of data relating to around 31 million customers; individual policy documents and medical reports retrievable on request
When it happened
Publicly surfaced August–September 2024
Made public
September 2024
How they got in
Not established publicly; the insurer confirmed unauthorised access and disputed the attacker's account of how the data was obtained
Attributed to
An actor operating under the handle "xenZen", who ran Telegram bots distributing the records
What it cost
Litigation against Telegram and the actor, an interim injunction from the Madras High Court, and a regulatory examination of a listed insurer

What was exposed: Names · Phone numbers · Physical addresses · Dates of birth · Identity and tax numbers · Medical reports · Insurance policy documents · Claim records

The data itself was ordinary for a breach of an insurer: names, addresses, identity numbers, policy documents, medical reports, claim histories. What was new was the shop front. Anyone who wanted a specific customer's file could ask a Telegram bot for it and receive it, one record at a time, the way you would query a directory.

What happened

In the second half of 2024, bots appeared on Telegram offering customer records belonging to Star Health, India's largest standalone health insurer. Reporting established that the documents returned were genuine, policy papers and medical reports belonging to real customers, complete with the identity and contact details attached to them. The actor behind the bots, operating under the handle "xenZen", claimed to hold data relating to tens of millions of customers.

The insurer confirmed that it had been the subject of unauthorised and illegal access, said its initial assessment had not found a widespread compromise of sensitive customer data, and stated that an investigation was underway. The actor publicly asserted that the data had been obtained with inside assistance; the company rejected that account. Those competing claims were never resolved in public, and this file does not adopt either.

What is not contested is the part that matters to the people in the records: authentic documents describing their health and identity were being handed out on request, and no statement from any party changed that while it was happening.

The distribution is the innovation

For most of the history of data breaches, stolen data has been awkward to use. It arrives as a compressed archive of database tables, tens of gigabytes, badly documented, and extracting one person's record requires the ability to load it and query it. That friction is a real, if unearned, protection. It limits the pool of people who can act on a leak to those with the tooling and patience to process one.

A chatbot removes it entirely. The interface is a message. The query is a name or a phone number. The response is a formatted document. Someone with a grudge against a neighbour, an ex-partner looking for an address, or a small-time fraudster picking targets no longer needs any technical capability at all, and the same interface serves a bulk buyer perfectly well.

Why this shape keeps spreading. Breach data is becoming a service rather than a file, and the incentives all point that way. Selling queries earns more, over a longer period, than selling a database once. It also lets the seller retain the corpus, price by volume, and keep operating after any single channel is taken down. Defenders should expect the gap between "a breach happened" and "anyone can look you up" to keep shrinking, because the market is actively engineering that gap away.

Going after the channel

Star Health's response was to sue Telegram and the actor in the Madras High Court, and to obtain interim orders directing that the bots be blocked. It is worth understanding why that was the sensible move rather than a distraction.

Once data is copied it cannot be recalled, so there is no legal remedy that restores the position. What a court can do is reach an intermediary: a platform with a corporate identity, a legal presence, and an interest in complying. Blocking the bots does not delete the data, does not stop it reappearing under new handles on the same platform or a different one, and does not help anyone whose documents were already retrieved. It does raise the cost and interrupt the convenience, which is the only lever available.

The case also placed a question in front of Indian courts that is not going away: what obligations a messaging platform has when its automation features are used to distribute stolen personal data at scale. Telegram's bot platform is not incidental to what happened here, it is the entire delivery mechanism, and the answer will shape how quickly the next one gets shut down.

The timeline

  1. August 2024: Telegram bots distributing Star Health customer documents begin operating.
  2. September 2024: Reporting verifies that the documents returned by the bots are genuine customer records.
  3. September 2024: Star Health confirms unauthorised access, says its initial assessment shows no widespread compromise of sensitive data, and begins an investigation.
  4. September 2024: The actor publicly alleges insider involvement; the company rejects the account.
  5. Late September 2024: Star Health obtains interim orders from the Madras High Court directing that the bots be blocked.
  6. Late 2024: Bots and mirrors resurface under new handles; the underlying corpus remains in circulation.

What it changed

The case arrived while India's Digital Personal Data Protection Act, passed in 2023, was still waiting on the rules that would give it operational teeth. That timing is the context for everything about the public handling of this incident: the absence of a clear statutory notification deadline, the reliance on stock exchange disclosure rather than customer notification as the primary public statement, and the fact that the most detailed account available to affected customers came from journalists rather than from anyone with a duty to inform them.

For the insurance sector specifically, it put a number on a risk that had been discussed abstractly. Insurers hold more sensitive data than banks do, financial detail plus medical history plus identity documents, retained for the life of a policy and beyond, and they have historically been supervised on solvency far more closely than on data handling. A leak that could be queried by name made that asymmetry difficult to ignore.

If you hold a health insurance policy in India

Start from the assumption that you cannot verify whether your documents were among those distributed, because no reliable per-customer check was ever published. Act on the exposure that would exist if they were.

The realistic risks are impersonation and targeted fraud. A caller who has your policy number, your sum insured and the date of a real claim sounds exactly like your insurer, and the scripts that follow are predictable: a claim that needs re-verification, a renewal at a corrected premium, a settlement pending a small processing payment. No insurer resolves any of those by asking for a one-time password, a UPI approval, or a transfer to an individual account. End the call and dial the number printed on your policy document.

There is also a quieter exposure with no procedural fix. Medical detail in circulation invites extortion against the specific people for whom a diagnosis is private, and the correct response to a message threatening disclosure is the same as for every other extortion attempt in this archive: the sender has a leaked file, not a relationship with you, and paying establishes only that your number is worth contacting again.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored, it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

What made this leak different from an ordinary database dump?

The delivery. Instead of a file posted for sale on a forum, the data was made available through Telegram chatbots: a user sent a query and the bot returned matching customer documents, including policy papers and medical reports. That turns a technical artefact into a consumer product. No forum account, no torrent, no ability to handle a multi-gigabyte database, just a chat window.

How did the attacker say they obtained the data, and did the company accept that account?

The actor publicly claimed the data had been obtained with inside help. Star Health rejected that account, said its initial assessment found no widespread compromise of sensitive customer data, and stated it was investigating. Those claims remain contested, and this file does not adopt either side's version. What is not in dispute is that genuine customer documents were being distributed.

What did Star Health do about it?

It sued Telegram and the actor in the Madras High Court and obtained interim orders directing that the bots be blocked. It is a reasonable response and an instructive one: the legal action targeted distribution rather than the breach, because distribution is the part with an identifiable intermediary that a court can order to act. Bots taken down can be replaced; the underlying copies do not go away.

Why is health insurance data worse than most breached data?

Because it combines identity with medical detail and financial exposure in one record. A policy document carries name, address, date of birth, identity numbers and the sum insured; a claim record adds what a person was treated for and when. That supports impersonation, targeted extortion, and fraud against both the customer and the insurer, and, unlike a password, none of it can be changed after the fact.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported, where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →