In the Star Health data breach case, the Supreme Court has refused to quash criminal proceedings against cybersecurity researcher Himanshu Pathak, leaving the competing versions of why he accessed and downloaded customer data to be tested before the trial court.
Thank you for reading this post, don't forget to subscribe!
New Delhi: The Supreme Court on Monday declined to interfere with the criminal proceedings against cybersecurity researcher Himanshu Pathak, accused by Star Health and Allied Insurance Company of unlawfully accessing and downloading about 8,000 files of customers’ personal, health and financial data, holding that the questions raised call for an assessment of evidence at trial [Himanshu Pathak v. State of Tamil Nadu and Anr.].
The matter was heard by a Bench of Chief Justice of India Surya Kant, Justice Joymalya Bagchi and Justice V. Mohana.
The case
According to Star Health, Pathak unlawfully accessed and downloaded customer data and threatened to publish it unless the company engaged his services. Pathak’s case is that he discovered critical vulnerabilities in the insurer’s systems and reported them responsibly, with no intention of misusing the data or extorting the company. The Madras High Court had earlier declined to quash the proceedings, and on August 6, 2026, the Supreme Court had directed him to appear before the XI Metropolitan Magistrate, Chennai, and furnish bail bonds.
The allegations remain untested. The Court has not expressed any view on the merits, and Pathak is presumed innocent.
Pathak’s submissions
Advocate Prashant Bhushan, for Pathak, argued that “the entire exercise was most bona fide.” He submitted that Star Health had not disclosed that a separate Policybazaar case had since been closed by the police, and pointed to earlier disclosures by his client, saying that “the Punjab National Bank thanked us and said that we have shut down this thing and we are now fixing it.”
“We have never published anybody’s data. Never put someone’s data out,” he said, adding that the conversation on record showed the company had sought Pathak’s help to fix the problem, and that he had quoted his fee only when asked whether they could engage him.
Star Health’s response
Senior Advocate Dr S. Muralidhar, for Star Health, described the communications on record and told the Bench, “This is not an ordinary person you’re dealing with.” The real question, he argued, was whether Pathak had unlawfully obtained and retained sensitive customer information and then used the existence of that information to exert pressure on the company.
Star Health Data Breach: Privacy Of Customers Implicated
The Bench questioned whether a cybersecurity researcher could, on his own, access and download data without authorisation. It observed that the moment sensitive personal information is removed from a company’s database, the privacy interests of the individuals whose information is contained in that data are implicated.
Noting that the matter raised factual questions about the circumstances in which the data was accessed, why it was downloaded and what was done with it afterwards, the Court held that these involved an assessment of evidence. It declined to interfere, leaving the competing allegations and Pathak’s defence to be examined before the trial court in accordance with law.
Case Title: Himanshu Pathak v. State of Tamil Nadu and Anr. [SLP(Crl) No. 13621 of 2026]
Bench: CJI Surya Kant, Justice Joymalya Bagchi and Justice V. Mohana, Supreme Court of India
Date of Hearing: October 5, 2026
Appearances: Advocate Prashant Bhushan for the petitioner; Senior Advocate Dr S. Muralidhar for Star Health and Allied Insurance Company
