01Summary
In September 2024, RansomHub claimed responsibility for breaching Star Health Insurance. The attackers exfiltrated approximately 31 million records containing policyholder names, phone numbers, email addresses, medical reports, tax IDs, and scanned identity documents. RansomHub published samples on Telegram and attempted to extort the company. The breach represented one of the largest healthcare data exposures in Indian history, drawing scrutiny from Indian regulators and CERT-In.
02Background
Star Health is India's largest standalone health insurance provider with over 31 million policyholders. The company processes vast amounts of sensitive medical and personal data, making it a high-value target for cybercriminals seeking health insurance information for fraud and identity theft.
03Key revelations
- 01Inadequate cybersecurity protections at one of India's largest insurers
- 02Scale of healthcare data vulnerable to ransomware groups
- 03RansomHub's growing capability to target major enterprises in emerging markets
04Technical analysis
RansomHub gained access through compromised credentials, exploiting weak multi-factor authentication. The group used living-off-the-land techniques to move laterally and exfiltrated data via encrypted channels over several days before deploying ransomware. Evidence suggested initial access may have occurred weeks before detection.
05Threat actor
RansomHub is a ransomware-as-a-service (RaaS) group that emerged in 2024, known for targeting healthcare, finance, and critical infrastructure. They operate a typical double-extortion model: data exfiltration followed by ransomware deployment, with public leaks used as leverage.
Aliases
- RansomHouse
- RansomHub Group
Attribution sources
- Telegram posts by RansomHub
- Media reports
- Star Health regulatory filings
06Victims and impact
The breach exposed deeply personal medical data of millions, creating risks of medical identity theft, insurance fraud, and social engineering. Star Health faced reputational damage, regulatory penalties, and a class-action lawsuit. Indian insurance regulators mandated enhanced cybersecurity protocols.
Evidence of breach
RansomHub published sample datasets on Telegram including policy documents and identity cards. The leaked data was independently verified by cybersecurity researchers and journalists.
Countries affected
- India
07Data exposed
Data types
- Policy Numbers
- Full Names
- Phone Numbers
- Email Addresses
- Medical Reports
- Lab Test Results
- Prescriptions
- Tax IDs (PAN)
- Scanned ID Cards (Aadhaar, Passport)
- Addresses
08Financial damage
Star Health incurred regulatory fines, legal costs from class-action suits, and reputational damage affecting customer acquisition.
09Timeline
- 2024-09-15Initial compromise (estimated by forensic analysis)
- 2024-09-20RansomHub announces breach on Telegram, publishes samples
- 2024-09-22Star Health confirms breach in regulatory filing
- 2024-09-25CERT-In launches investigation
- 2024-10-01Class-action lawsuit filed
- 2024-10-15IRDAI mandates enhanced security measures across insurance sector
10Reaction and fallout
Public reaction
Widespread outrage among policyholders and calls for stronger data protection laws in India. Many customers reported phishing attempts following the leak.
Political impact
Prompted Indian parliamentary discussions on data protection and cybersecurity requirements for insurance companies.
11Legal
Investigation by CERT-In and Indian insurance regulator IRDAI. Class-action lawsuit filed in India.
Civil lawsuits
- Class-action lawsuit on behalf of affected policyholders
12Aftermath
Policy changes
- IRDAI mandated enhanced cybersecurity audits for all insurance companies
Regulatory changes
- Stricter data protection requirements under India's Digital Personal Data Protection Act
Security improvements
- Implementation of mandatory multi-factor authentication
- Regular security audits for insurance sector
13Significance and legacy
Significance
The Star Health breach was one of the largest healthcare data exposures in Asia and demonstrated that major Indian enterprises remain vulnerable to sophisticated ransomware groups despite regulatory oversight.
Legacy
The breach accelerated India's regulatory push for mandatory data protection compliance and highlighted the vulnerability of the healthcare insurance sector to ransomware-driven data exfiltration.
14Disclosure and media
- Authentication
- Independent verification by cybersecurity researchers
Publishing organisations
- The Hindu
- Bloomberg
- TechCrunch
- BleepingComputer
16Field notes
- 01Star Health is India's largest standalone health insurer with over 30% market share.
- 02The breach was carried out by RansomHub, a group that operates a ransomware-as-a-service model and has claimed multiple high-profile victims in 2024.
17Resolution
Star Health engaged cybersecurity firms for incident response and remediation. The company notified affected customers and implemented enhanced security measures under regulatory direction.
18Sources
Official documents
- Star Health regulatory filing to stock exchanges
References
- [1]BleepingComputer
- [2]The Hindu
- [3]TechCrunch
- [4]CERT-In advisory









