STAR HEALTH’S PUBLIC RECORD: A DATA BREACH, A ₹3.39-CRORE FINE, 13,000 OMBUDSMAN COMPLAINTS — AND STILL NO ACCOUNTING FOR THE POLICYHOLDER
An investigative examination of Star Health and Allied Insurance Company Limited, built only on exchange filings, regulator orders, court records and independently reported facts as of 29 August 2026.
Chennai’s largest standalone health insurer sells a simple promise: when the hospital bill arrives, the company will stand between the patient and ruin. The public record of Star Health and Allied Insurance Company Limited — CIN L66010TN2005PLC056649, IRDAI Registration No. 129 — tells a colder story. It is a story of a 2024 leak of authentic medical files, a regulator who finally put a price on the company’s cyber sloppiness, an Ombudsman docket that reads like a factory of repudiations, a GST basket running into hundreds of crores of disputed tax, and a corporate reflex that is quicker to sue a researcher than to explain how patients’ diagnoses ended up on Telegram.
This is not a rumour mill. It is what Star itself told the stock exchanges, what IRDAI put in an order, what Reuters authenticated, and what the Council for Insurance Ombudsmen counted.
The breach that was “limited” until it wasn’t
In August 2024 a threat actor calling itself xenZen emailed Star’s top brass, claimed access to customer data, and demanded about US$68,000. Star’s first market line was the familiar corporate shrug: limited incident, no widespread compromise, operations unaffected. Then Reuters did what the company’s press notes would not. It downloaded more than 1,500 policy and claim files circulating through Telegram bots and checked them with policyholders. The papers were real. Names. Addresses. Phone numbers. Copies of identity documents. Diagnoses. Claim files. The intimate paperwork of illness, sitting on a messaging app.
The hacker advertised a much larger haul — roughly 31.2 million datasets and 7.24 terabytes. Those headline numbers have never been independently verified. That is not a courtesy to Star. It is a refusal to launder a criminal’s marketing into fact. What is fact is this: enough genuine medical files left the building to be sampled, published and confirmed by a global news agency. For a health insurer, that is not a “glitch.” It is a betrayal of the only asset the customer cannot replace — the medical file.
The same actor alleged that Star’s Chief Information Security Officer had sold or facilitated access. Star denied it. Forensic work commissioned by the company called the purported communications fabricated. No court or regulator has found that the CISO sold the data. Fine. Record that. Then record the other half: IRDAI still concluded the company’s information-security controls were broken badly enough to punish. A clean chit for one officer is not a clean bill for the institution that stored the files.
Star did what well-lawyered companies do. It sued Telegram, Cloudflare and the unidentified hacker. On 14 July 2025 the Madras High Court declared the hacking illegal and issued a permanent injunction. That order is a win — for Star as plaintiff. It does not rewind the leak. It does not put the diagnoses back in the vault. It does not explain how a “limited” incident produced authenticated medical documents on the open internet.
The sequel was grotesque. Threatening packages, including bullets, were sent to MD and CEO Anand Roy, his wife, and CFO Nilesh Kambli. Tamil Nadu cyber police arrested a Telangana man, Mohammed Irfan, alleged to have been hired as a courier. He is not a Star director. The arrest does not wash the company. It underlines how completely the incident escaped the building — first the data, then the intimidation.
IRDAI’s bill: ₹3.39 crore, a warning, and no poetry
On 25 July 2025, the Insurance Regulatory and Development Authority of India stopped speaking in advisories. It imposed a monetary penalty of ₹3.39 crore and a formal warning for violations of the IRDAI Information and Cyber Security Guidelines, 2023. Star’s own BSE/NSE filing the next day said the penalty concerned “certain aspects pertaining to safeguard of data and cyber security.” The company evaluated an appeal to the Securities Appellate Tribunal. Its later results recorded that the penalty was paid in September 2025. No published final order setting that penalty aside has been located.
Read that slowly. India’s insurance regulator looked at Star’s cyber hygiene after a year in which authentic patient files were hawked on Telegram, and it did not issue a pep talk. It issued a bill. Three crore thirty-nine lakh is not a rounding error in a press release. It is a finding that the company that monetises illness failed the basic duty of locking the cabinet.
This was not Star’s first brush with IRDAI language. In August 2015 the regulator warned the company over an advertisement calling itself “Number One” — a claim IRDAI treated as potentially misleading because it rested on selected ranking criteria. An 2018 inspection produced a June 2020 show-cause; the prospectus says the 30 September 2020 final communication closed without a monetary penalty and left advisories. A December 2024 show-cause followed a general inspection from 31 January to 11 February 2022. None of that history is a criminal conviction. All of it is a pattern: the regulator keeps having to write to this company.
On 25 August 2026, days before this newspaper’s cut-off, Star disclosed fresh IRDAI directions on portability cases for FY 2024–25 and FY 2025–26 and on review of specified claims, with a compliance report due in four months. The filing was careful to shout the good news: Penalty: Nil. Restriction: Nil. Sanction: Nil. That is not absolution. That is a regulator still standing in the doorway, telling the largest standalone health insurer to reopen files it would rather leave shut. When a company boasts “nil penalty” as the headline, listen to the instruction underneath: look again at the claims you already decided.
The Ombudsman’s ledger: 13,308 complaints, 10,196 repudiation fights
If the breach is the scandal of what left the server, the Ombudsman reports are the scandal of what happens when the customer is still inside the policy.
The Council for Insurance Ombudsmen’s FY 2023–24 numbers are not ambiguous. Star Health attracted 13,308 complaints — the most in the health segment. Of those, 10,196 were about full or partial claim repudiation. The Ombudsman system issued 7,506 recommendations or awards against the company, aggregating about ₹60.54 crore. On a per-lakh-lives basis the ratio was 63 — again the worst among the names that dominate the table. CARE Health, Niva Bupa and the public-sector majors sat far behind on raw volume. Star did not merely lead the table. It lapped it.
FY 2024–25 did not produce a redemption arc. The Ombudsman workload — opening pendency plus new complaints — stood at 12,186. Against about 23.78 million persons covered, that is roughly 51 complaints per lakh lives, still the highest ratio in the published comparison. CARE had 4,423 complaints; Niva Bupa 3,983. Star remained the industry’s complaint magnet.
Insurers love a particular sentence: complaint numbers do not mean every complaint was upheld. Correct. Also incomplete. Ten thousand repudiation disputes in a single year is not “a few unhappy customers.” It is an operating model colliding with the people who paid the premium. Health insurance is not a lifestyle app. It is sold at the kitchen table to families who believe the brochure. When the brochure meets the ward, Star’s public statistics say the argument too often ends in a no.
District commissions and High Courts have been writing the footnotes. In April 2026 the Gauhati High Court dismissed Star’s challenge to an Ombudsman award. The Punjab and Haryana High Court the same month upheld an award of about ₹72,617. The Kerala High Court in March 2026 declined to disturb a Permanent Lok Adalat award on a repudiated health claim. A Bengaluru consumer commission in March 2026 directed payment of about ₹4.5 lakh plus 9 per cent interest, ₹20,000 for mental agony, ₹10,000 costs and restoration of the policy in a breast-cancer dispute. Chandigarh’s District Consumer Disputes Redressal Commission directed payment of ₹25 lakh with interest to the legal heirs of a deceased policyholder after finding the repudiation ran into IRDAI’s moratorium logic — you do not get to invent a pre-existing disease after years of continuous cover unless you can prove fraud. Smaller benches have been ordering reimbursements in the tens of thousands: dengue bills, partial hospital settlements, litigation costs piled on top of the original claim.
Yes, there are orders that uphold Star’s repudiation where the insured suppressed material facts. Those cases exist. They do not cancel the pile. A company that wins some and loses thousands is not “vindicated.” It is a company whose default setting appears to be: deny first, litigate second, pay when a forum makes it unavoidable.
In March 2026 a consumer-execution court issued an attachment warrant after delay in complying with an award. The Delhi High Court stayed the warrant on 18 March 2026, noting the delay was a single day. That stay is not a medal. It is a picture: even after a forum has spoken, the insured still had to watch the machinery of execution grind because the insurer was late.
GST: not a raid, not a conviction — and not a small problem
No GST raid on Star Health has been located in the public record. No criminal GST conviction has been located. Anyone who converts every assessment order into “GST fraud” is doing the company’s work by handing it an easy defamation defence. The actual record is bad enough without the embroidery.
On 14 February 2024 the Large Taxpayers Unit, Chennai, issued a demand under Section 73 of the CGST Act for non-payment of GST on reinsurance commission for April 2018–March 2019: about ₹170.67 crore in tax and about ₹8.67 crore in penalty. Star told the exchanges the issue was industry-wide, that it had a strong case, and that it would appeal. The outcome, it admitted, could not be predicted. That is corporate code for: a nine-figure tax fight is sitting on the books and we would like you not to stare.
A DGGI Mumbai show-cause dated 6 October 2023 alleged unpaid GST as a follower insurer in co-insurance from July 2017 to March 2023 — ₹38.99 crore, with no penalty quantified in the disclosed notice.
On 21 March 2025 came the carpet-bombing: 25 orders across Haryana, Delhi, Maharashtra, Tamil Nadu, Telangana and Karnataka, alleging non-payment of GST on co-insurance follower transactions, non-disclosure and non-issuance of invoices. Tax ₹24,66,66,863 plus an equal penalty — ₹49,33,33,726 — plus interest. Maharashtra alone accounted for nearly ₹19.50 crore of the tax-plus-penalty pile; Tamil Nadu ₹16.24 crore. Star said it had strong grounds and would file appeals and writs. Strong grounds are what every assessee claims on Day One. The orders exist regardless.
One piece of the pile did fall. A Chennai South order dated 24 January 2025 — ₹33.05 crore tax plus an equal penalty under Section 74 — was set aside by the Madras High Court on 5 April 2025 in W.P. No. 8057 of 2025. Star disclosed the win to the exchanges. Credit it. Then notice what the win is: a court telling the department to stop, not a finding that Star’s GST position is pristine across India. Tamil Nadu and Uttar Pradesh added smaller excess-ITC penalty orders in December 2025; the UP figure is ₹75,27,772.28 — ₹75.28 lakh, not the ₹75.28 crore that sloppy secondary reports invented. Even the corrections are a tell: the company’s tax story is so large that journalists lose a zero and the number still sounds plausible.
The 2021 IPO prospectus had already listed four direct-tax disputes totalling about ₹105.11 crore across assessment years 2009–10 to 2014–15. Those were assessment fights, not income-tax raids. No IT search of Star Health was located. The picture is not of midnight raids. It is of a listed insurer living for years inside a fog of tax demands it keeps describing as technical and industry-wide while the rupee figures keep arriving in crores.
The researcher, the FIR, and the company’s preferred enemy
While patient files were circulating on Telegram, Star found a different adversary to take to court: Himanshu Pathak, a cybersecurity researcher trading as CyberX9.
Pathak’s account is that while checking a family policy he found a legacy API that answered unauthenticated requests if you changed the policy number — a hole, he says, in Star’s own plumbing. He says he told the company and CERT-In. Star’s account, now in a charge-sheet narrative, is that he accessed systems without authority, extracted on the order of 8,000 policy records, and demanded consultancy fees of US$65,000 a year plus US$3,000 a month with a threat to leak. The Madras High Court dismissed his writ appeals seeking a regulatory probe. The Supreme Court in July 2026 heard him with some visible irritation at both sides — one judge needling Star about what it had actually fixed and what personal data is worth on the dark web; another treating Pathak’s conduct as more marketplace than public spirit. Oral remarks urged settlement. They were not a judgment on merits. In early August 2026 the Supreme Court granted Pathak interim bail and sent him to the Chennai trial court.
Put the sequence in daylight. A company that lost authentic medical files to a Telegram actor spent institutional energy criminalising a man who says he found the door unlocked. Maybe a trial court will find Pathak crossed the line from research into extraction and demand. Maybe it will not. Either way, the optics are pitiless: the patients whose files leaked are still waiting for a full public accounting of how many records moved. The researcher is the one being told to furnish bail bonds.
Star was the complainant in older employee-fraud FIRs as well — 2014, 2016, 2021 matters disclosed in the prospectus, one of them ending in acquittal for lack of evidence. Those cases are not stains on the company as accused. They are a reminder that Star knows how to walk into a police station when it is the victim. The 2024 leak was also a crime against Star. The difference is that the leak was a crime against its customers first.
Directors: no handcuffs in the public record — and no halo either
A responsible investigation does not invent arrests. No reliable public record was located of the arrest of a current Star Health director. No ED raid, ECIR, PMLA prosecution or ED attachment against the company or its sitting board was found. No SFIO case. No state EOW FIR against the company. No admitted NCLT insolvency of Star as corporate debtor. No RERA file — Star is not a builder. Anyone selling those headlines is not investigating. They are fabricating.
The board after the 28 August 2026 AGM, following the 15 July 2026 retirements of Rajeev K. Agarwal and Rajni Sekhri Sibal, includes Rajeev Kher, Anand Roy, Himanshu Walia, Amitabh Jain, Anisha Motwani, Rohit Bhasin, Sumir Chadha, Deepak Ramineedi and Utpal Sheth.
What the record does hold on names around that table is not nothing.
Utpal Sheth, now a non-executive director on the promoter side, paid ₹66,93,750 under a 14 July 2021 SEBI settlement in the Aptech unpublished-price-sensitive-information matter. The order disposed of the proceedings without admission or denial. It was not a Star Health trade. It is still a market-regulator settlement against a man who sits on Star’s board. A historical Maharashtra Ownership of Flats Act private complaint that led to process against him in Thane in 2013 later shows settlement consent terms; no conviction or arrest was located. Unrelated to Star — and still part of the director’s public baggage.
Rajeev K. Agarwal, while he was an independent director, carried a 1 March 2018 CBI FIR from his earlier Forward Markets Commission life and the recognition of MCX as a nationwide exchange. The CBI searched locations in that investigation. The public material does not establish that Star’s offices were the target or that the alleged conduct arose from Star’s insurance business. In February 2024 a special CBI court accepted the closure report: the investigation had not substantiated cheating, corruption or dishonest intent. He left Star’s board on 15 July 2026. Closed and unrelated — and a reminder that “independent director” is a title, not an insurance policy against history.
V. Jagannathan, the founder, is no longer the operational face. Anand Roy, who has been on the board since 2019 and MD & CEO through the breach years, is. The threatening packages went to his house. The IRDAI cyber order landed on his watch. The Ombudsman tables accumulated on his watch. Leadership is not only the interview on a business channel. It is the year the medical files left and the year the regulator sent the invoice.
Hospitals, tariffs, cashless — the other war Star picked
In Ahmedabad in 2023 and again in 2025, and nationally through the Association of Healthcare Providers India in September–October 2025, Star’s hospital relationships turned into a public brawl. The company accused hospitals of tariff violations and billing games. Hospital bodies accused Star of stale rate lists, coercive cuts, query-by-query attrition, deductions that look like a second underwriting, and the nuclear option: pulling cashless so the patient pays at the counter. Cashless was suspended at some Ahmedabad hospitals, then restored after talks. AHPI withdrew an advisory after similar theatre. No criminal fraud finding against Star was located in that fight.
Patients do not live in the joint statement. They live in the six hours when cashless is “under review” and the family is being asked for a deposit. A health insurer that cannot keep a stable cashless network is not running a partnership. It is running a hostage exchange with the hospital and using the patient as the currency.
The small print Star would rather you never read aloud
The IPO prospectus disclosed a 29 January 2021 FIR by Novex Communications under Sections 51 and 63(a) of the Copyright Act: copyrighted songs at the 2019 Sales Managers’ Convention, no licence. No charge-sheet as of that disclosure. The matter was waved away as not financially material. In December 2025, Phonographic Performance Limited obtained an ad-interim Bombay High Court injunction restraining Star from unlicensed public performance of PPL’s repertoire — a civil IP humiliation, not a jail term. A company that litigates claims to the last rupee apparently could not organise a music licence for its own party. The metaphor writes itself.
Historical “material” civil matters in the prospectus totalling about ₹462.40 crore were largely shareholder, award-enforcement and garnishee fights. They are not ED attachments. They are also not a portrait of a quiet company.
What the record is — and what it is not
Here is the line this investigation will not cross, because crossing it would make the rest easier to dismiss.
Star Health and its current directors have not, on the open record through 29 August 2026, been shown as subjects of an ED money-laundering prosecution, a hawala case, an SFIO reference, a state EOW raid, a GST search, an income-tax raid, or an admitted insolvency. There is no located criminal conviction for cheating against the company or a sitting director. The 2018 CBI case around a former director is closed and unconnected to selling health policies. Employee-fraud FIRs were filed by Star. The man arrested over the bullet packages was not a director.
Use those facts. Do not inflate them. The company’s lawyers are waiting for the inflated version.
What remains after the deflation is damning enough.
This is a listed insurer that:
- let authentic medical and identity documents reach Telegram bots, then spent a year insisting the adjective “limited” still applied;
- paid ₹3.39 crore to IRDAI for cyber-control failures and collected a warning in the same envelope;
- generated 13,308 Ombudsman complaints in a single year, 10,196 of them over repudiation, and 7,506 awards or recommendations worth about ₹60.54 crore;
- still led the complaint tables the following year with a 12,186 workload and 51 complaints per lakh lives;
- is fighting GST demands that include a ₹170-crore-plus reinsurance order and a ₹49.33-crore multi-state co-insurance pile, even after a Madras High Court set-aside of one ₹33-crore-plus order;
- answers a researcher’s vulnerability claim with a criminal case while the original leak’s full scale remains a number only the hacker will swear to;
- and treats “nil penalty” on an August 2026 IRDAI portability-and-claims direction as a press victory rather than a homework note.
Health insurance is a contract written in fear. People buy it because they have seen what a week in intensive care does to a middle-class balance sheet. Star Health sold that fear at industrial scale — hundreds of offices, thousands of hospitals on the network list, lakhs of agents. The public record says the company is rather better at collecting the premium than at behaving, when the file is opened, as if the human being on the form were the point of the enterprise.
The data left. The fine was paid. The Ombudsman kept counting. The tax papers kept coming. The researcher was sent toward a trial court. The policyholder, as usual, is the last person in the room still being asked to produce one more document.
Reporting based on Star Health exchange filings, IRDAI and SEBI orders, Madras and Bombay High Court records, Supreme Court reporting on the Pathak matter, Council for Insurance Ombudsmen annual figures, and contemporaneous accounts by Reuters and business dailies. Sealed FIRs and undigitised district files, if they exist, are outside this record.



