EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2024-star-health-insurance-breach
076/430

File EL-0355CriticalResolvedData Breach / Ransomware / Extortion with Data Exfiltration

Star Health Insurance Data Breach

Also filed as Star Health Breach · Star Health RansomHub Leak

Star Health, India's largest health insurer, suffered a major ransomware and data exfiltration attack by the RansomHub group. Over 31 million policyholder records were compromised, including sensitive medical data, identity documents, and financial information.

  • #healthcare
  • #pii
  • #insurance-data
  • #ransomware
  • #india
  • #ransomhub
  • #medical-records
Notoriety9/10
Event
20 Sept 2024
Disclosed
20 Sept 2024
Target
Star Health and Allied Insurance Co.
Actor
RansomHub
Scale
31.0M people
Status
Resolved

01Summary

In September 2024, RansomHub claimed responsibility for breaching Star Health Insurance. The attackers exfiltrated approximately 31 million records containing policyholder names, phone numbers, email addresses, medical reports, tax IDs, and scanned identity documents. RansomHub published samples on Telegram and attempted to extort the company. The breach represented one of the largest healthcare data exposures in Indian history, drawing scrutiny from Indian regulators and CERT-In.

02Background

Star Health is India's largest standalone health insurance provider with over 31 million policyholders. The company processes vast amounts of sensitive medical and personal data, making it a high-value target for cybercriminals seeking health insurance information for fraud and identity theft.

03Key revelations

  1. 01Inadequate cybersecurity protections at one of India's largest insurers
  2. 02Scale of healthcare data vulnerable to ransomware groups
  3. 03RansomHub's growing capability to target major enterprises in emerging markets

04Technical analysis

RansomHub gained access through compromised credentials, exploiting weak multi-factor authentication. The group used living-off-the-land techniques to move laterally and exfiltrated data via encrypted channels over several days before deploying ransomware. Evidence suggested initial access may have occurred weeks before detection.

05Threat actor

RansomHub is a ransomware-as-a-service (RaaS) group that emerged in 2024, known for targeting healthcare, finance, and critical infrastructure. They operate a typical double-extortion model: data exfiltration followed by ransomware deployment, with public leaks used as leverage.

Aliases

  • RansomHouse
  • RansomHub Group

Attribution sources

  • Telegram posts by RansomHub
  • Media reports
  • Star Health regulatory filings

06Victims and impact

The breach exposed deeply personal medical data of millions, creating risks of medical identity theft, insurance fraud, and social engineering. Star Health faced reputational damage, regulatory penalties, and a class-action lawsuit. Indian insurance regulators mandated enhanced cybersecurity protocols.

Evidence of breach

RansomHub published sample datasets on Telegram including policy documents and identity cards. The leaked data was independently verified by cybersecurity researchers and journalists.

Countries affected

  • India

07Data exposed

Data types

  • Policy Numbers
  • Full Names
  • Phone Numbers
  • Email Addresses
  • Medical Reports
  • Lab Test Results
  • Prescriptions
  • Tax IDs (PAN)
  • Scanned ID Cards (Aadhaar, Passport)
  • Addresses

08Financial damage

Star Health incurred regulatory fines, legal costs from class-action suits, and reputational damage affecting customer acquisition.

09Timeline

  1. 2024-09-15Initial compromise (estimated by forensic analysis)
  2. 2024-09-20RansomHub announces breach on Telegram, publishes samples
  3. 2024-09-22Star Health confirms breach in regulatory filing
  4. 2024-09-25CERT-In launches investigation
  5. 2024-10-01Class-action lawsuit filed
  6. 2024-10-15IRDAI mandates enhanced security measures across insurance sector

10Reaction and fallout

Public reaction

Widespread outrage among policyholders and calls for stronger data protection laws in India. Many customers reported phishing attempts following the leak.

Political impact

Prompted Indian parliamentary discussions on data protection and cybersecurity requirements for insurance companies.

11Legal

Investigation by CERT-In and Indian insurance regulator IRDAI. Class-action lawsuit filed in India.

Civil lawsuits

  • Class-action lawsuit on behalf of affected policyholders

12Aftermath

Policy changes

  • IRDAI mandated enhanced cybersecurity audits for all insurance companies

Regulatory changes

  • Stricter data protection requirements under India's Digital Personal Data Protection Act

Security improvements

  • Implementation of mandatory multi-factor authentication
  • Regular security audits for insurance sector

13Significance and legacy

Significance

The Star Health breach was one of the largest healthcare data exposures in Asia and demonstrated that major Indian enterprises remain vulnerable to sophisticated ransomware groups despite regulatory oversight.

Legacy

The breach accelerated India's regulatory push for mandatory data protection compliance and highlighted the vulnerability of the healthcare insurance sector to ransomware-driven data exfiltration.

14Disclosure and media

Authentication
Independent verification by cybersecurity researchers

Publishing organisations

  • The Hindu
  • Bloomberg
  • TechCrunch
  • BleepingComputer

15Related files

Related events

  • 2024-change-healthcare-attack
  • 2024-medibank-breach-2022

16Field notes

  1. 01Star Health is India's largest standalone health insurer with over 30% market share.
  2. 02The breach was carried out by RansomHub, a group that operates a ransomware-as-a-service model and has claimed multiple high-profile victims in 2024.

17Resolution

Star Health engaged cybersecurity firms for incident response and remediation. The company notified affected customers and implemented enhanced security measures under regulatory direction.

18Sources

Official documents

  • Star Health regulatory filing to stock exchanges

References

  1. [1]BleepingComputer
  2. [2]The Hindu
  3. [3]TechCrunch
  4. [4]CERT-In advisory
Fact sheetEL-0355

Dates

Event
20 Sept 2024
Started
15 Sept 2024
Ended
15 Oct 2024
Duration
30 days
Discovered
20 Sept 2024
Disclosed
20 Sept 2024
Ongoing
No

Target

Organisation
Star Health and Allied Insurance Company Limited
Type
Insurance Company
Sector
Healthcare & Insurance
Country
India

Actor

Name
RansomHub
Type
Criminal Gang
Motivation
Financial extortion and data sale on dark web forums
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
31,000,000
Sensitivity
Highly Sensitive
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.