Justice Joymalya Bagchi made the observation during a hearing on a plea concerning alleged data vulnerabilities in Star Health’s systems.
What Happened
The Supreme Court on Thursday, 1 October 2026, heard a plea filed by cybersecurity researcher Himanshu Pathak concerning alleged vulnerabilities in the systems of Star Health and Allied Insurance Company. The bench comprised Justices Joymalya Bagchi and V Mohana.
During the hearing, Justice Bagchi observed that it is “common knowledge” that personal data of Indians is being traded on the dark web. The observation came after Senior Advocate S Muralidhar, appearing for Star Health, told the Court that the insurer had taken extensive security measures and now continuously monitors its systems. As reported by Bar and Bench, Muralidhar responded that the dark web is beyond anyone’s control and that its existence does not by itself make Star Health complicit.
Justice Bagchi also stressed that cybersecurity measures cannot remain static. As technology used to access data changes, he said, firewalls and other safeguards must also be updated. Muralidhar said Star Health therefore uses different audit agencies and monitors its systems through external agencies. He maintained that the company’s data is secure and described its cybersecurity measures as completely foolproof. These were submissions by Star Health’s counsel, not findings by the Court.
Pathak’s side, represented by Advocate Prashant Bhushan, presented a different account. Bhushan told the Court that, following the 2024 incident, an insider had allegedly provided access to the company’s wider data and that Pathak could send data relating to government employees and Supreme Court judges. He also referred to a September 2026 statement by a person described by counsel as a hacker, who allegedly claimed to have received the data from a Star Health employee. These assertions were made as submissions on Pathak’s behalf and were not established by the Court at the hearing.
The bench also expressed reservations about the manner in which Pathak had approached the issue. Justice Bagchi questioned whether accessing a system to demonstrate a vulnerability was comparable to a locksmith breaking into a house and then pointing out that its security was inadequate. Bhushan responded that others could access the information and that Pathak had brought the vulnerability to attention.
The Court reportedly suggested that Pathak pursue his concerns through the civil proceedings already pending between the parties. Justice Bagchi asked him to withdraw the petition without prejudice to his rights and contentions, while Bhushan urged the Court to preserve the public-interest dimension of the matter. He also suggested that an amicus curiae could be appointed, even without Pathak remaining a formal party. No report indicates that the Court appointed an amicus or that the petition was withdrawn on 1 October.
The matter is next listed for 7 October 2026, according to the report of the hearing. No final order from the 1 October hearing has been reported.
Background & Context
Pathak, proprietor of CyberX9 and a Star Health policyholder, says he discovered vulnerabilities while accessing his own policy information through the insurer’s web portal. According to the account recorded in earlier proceedings, he claimed those vulnerabilities could allow access to information relating to other policyholders. Star Health disputes his account and has maintained that his access to its systems was unauthorised.
The dispute has produced parallel civil and criminal proceedings. In October 2024, Justice M Dhandapani of the Madras High Court dismissed Pathak’s writ petitions seeking directions to government ministries and regulators concerning his complaints. The Court noted that a civil suit concerning the same dispute was already pending and that criminal proceedings had also been initiated.
The Madras High Court’s Division Bench later dismissed Pathak’s writ appeals in April 2026. The bench of Chief Justice Sushrut Arvind Dharmadhikari and Justice G Arul Murugan held that the issues were already sub judice in the pending proceedings and declined to interfere.
The dispute subsequently reached the Supreme Court. On 24 July 2026, the Court, in a bench including CJI Surya Kant, Justice Bagchi and Justice Mohana, asked Star Health to explore whether the dispute could be brought to an end. LiveLaw reported that the Court did so without expressing a view on the merits.
On 6 August, the Supreme Court directed Pathak to appear before the XI Metropolitan Magistrate in Chennai, furnish bail bonds and seek regular bail in the criminal case. The Court also directed Star Health to place an independent cybersecurity audit report on record.
Key Details
- Court/Forum: Supreme Court of India.
- Date: 1 October 2026.
- Bench: Justice Joymalya Bagchi and Justice V Mohana.
- Case Title: Himanshu Pathak v. Ministry of Electronics and Information Technology & Ors.
- Petitioner: Himanshu Pathak, represented by Advocate Prashant Bhushan.
- Star Health’s representation: Senior Advocate S Muralidhar.
- Issue before the Court: A plea concerning alleged vulnerabilities in Star Health’s systems and the handling of Pathak’s complaints.
- Lower-court history: The Madras High Court’s single judge dismissed the writ petitions in October 2024; its Division Bench dismissed the connected writ appeals in April 2026.
- Related proceedings: Civil and criminal proceedings between Pathak and Star Health remain relevant to the dispute.
- Current status: The matter is to be heard further on 7 October 2026. No final order from the 1 October hearing has been reported.
Why It Matters
Justice Bagchi’s observation places a broader data-security concern at the centre of a dispute that otherwise involves sharply contested accounts between a cybersecurity researcher and a private insurer.
The significance of the observation lies partly in its setting. Star Health is an insurer holding highly sensitive personal information, while the Court was considering competing submissions about how vulnerabilities should be identified, reported and addressed. The hearing therefore brought an important question into focus: where should the line be drawn between legitimate security research and unauthorised access to protected information?
The Court’s locksmith analogy captures that tension. Pathak’s side says identifying vulnerabilities can serve a public purpose and that he did not improperly obtain access in the manner alleged by Star Health. Star Health, on the other hand, disputes that characterisation and has maintained that Pathak’s access was unauthorised. Neither account was finally resolved by the 1 October hearing.
There is a second question beneath the immediate dispute. The bench appeared to have reservations about Pathak’s bona fides and about allowing the petition to become a vehicle for public-interest scrutiny, while Bhushan argued that the underlying data-security concerns were serious enough to warrant continued judicial attention. His suggestion of an amicus mechanism pointed towards a possible way of examining the broader issue without necessarily making Pathak’s individual dispute the sole vehicle for doing so.
For law students and practitioners, the hearing illustrates the difficulty of separating the merits of a cybersecurity disclosure from the legal consequences of the method used to discover it. It also shows why judicial observations during an ongoing hearing must be distinguished from findings after evidence has been tested.
At this stage, the Supreme Court has not determined whether Pathak’s conduct was lawful, whether Star Health’s systems were insecure, or whether either side’s allegations are ultimately established. Those questions remain part of the wider litigation.
Reactions
Justice Bagchi’s observation that it is “common knowledge” that data of Indians is traded on the dark web was made during the hearing in response to Star Health’s submissions about the security of its systems.
Muralidhar maintained that the dark web is beyond anyone’s control and argued that its existence does not make Star Health complicit. He also told the Court that the company continuously monitors its systems and uses external audit agencies.
Bhushan, appearing for Pathak, argued that the matter raised a serious public-interest concern and urged the Court not to close that aspect of the case. He suggested that an amicus curiae could assist the Court in examining the broader data-security questions.
No separate reactions from regulators, activists or public organisations were identified in the material reviewed for this report.
Closing
The 1 October hearing did not resolve the competing accounts surrounding Star Health’s systems or Pathak’s conduct. Instead, it brought the wider question of personal-data security into sharper focus, with the Supreme Court expressly commenting on the circulation of Indians’ data on the dark web.
The next hearing is scheduled for 7 October 2026. Until then, the central questions surrounding the alleged vulnerabilities, the conduct of the parties and the appropriate scope of any public-interest inquiry remain unresolved.
Opportunities don’t wait. Neither should you.
Join 1 Lakh+ law students connected with Lexibal and stay updated with internships, opportunities, competitions and important updates.
Join WhatsApp Channel
