Star Health Data Breach Case: Supreme Court Refuses To Quash Criminal Proceedings Against Himanshu Pathak

The Supreme Court on Monday declined to interfere with the criminal proceedings initiated against cybersecurity researcher Himanshu Pathak for allegedly accessing and downloading sensitive customer data from Star Health and Allied Insurance Company without authorisation. A bench of Chief Justice Surya Kant, Justice Joymalya Bagchi, and Justice V. Mohana dismissed Pathak’s Special Leave Petitions challenging a Madras High Court order that refused to quash the case. However, the Court made permanent the interim bail granted on August 6, allowing Pathak to raise all his defences before the trial court.

The decision underscores the fine line between legitimate vulnerability research and potential criminal overreach, particularly when personal data is involved. The Supreme Court observed that the factual disputes—including Pathak’s intent, the extent of data downloaded, and the nature of his communications with Star Health—could not be resolved at the quashing stage under Section 482 of the Code of Criminal Procedure (CrPC).

Background of the Dispute

Star Health’s complaint alleges that Pathak unlawfully accessed and downloaded approximately 8,000 files containing customers’ personal, health, and financial information. The insurer further claims that Pathak subsequently sought to pressure the company by referring to the possible publication of the data while offering cybersecurity services. Pathak, on the other hand, maintains that he discovered critical vulnerabilities in Star Health’s systems, reported them to the company and the cybersecurity platform ‘certain’, and sought corrective action without any intention to misuse the information.

The case gained attention as it raises questions about the legal boundaries of ethical hacking and responsible disclosure. Pathak’s defence points to a separate FIR filed by Policybazaar.com, which was later closed by the police after investigators found that Pathak had informed the company about security vulnerabilities and leakage of sensitive data. That closure report, according to Pathak’s counsel, supports his claim of bona fide research.

Arguments Before the Apex Court

Pathak’s Defence: A Good Samaritan in Cybersecurity

Senior Advocate Prashant Bhushan, appearing for Pathak, argued that his client had acted as a “good Samaritan” by identifying vulnerabilities and reporting them. He emphasised that Pathak had previously reported security flaws to organisations such as Punjab National Bank, Vodafone, and CDSL, all of which acknowledged the reports and took corrective action. Bhushan submitted that the downloaded material was used solely to demonstrate the extent of the vulnerability to Star Health and was never published or supplied to unauthorised parties.

“The entire exercise was most bona fide. There was no intention, in fact, the proposal for business. Otherwise, we wouldn't have reported it to certain and to the company itself,” Bhushan argued. He also highlighted that the Policybazaar case was closed after investigation, indicating a pattern of responsible disclosure.

Star Health’s Position: Beyond a Routine Disclosure

Senior Advocate S. Muralidhar, representing Star Health, countered by drawing the Court’s attention to the communications between Pathak and the insurer. One email, cited by Muralidhar, referred to plans to publish articles about the security issues through national and international publications after the vulnerabilities were fixed. Star Health characterised this as an implied threat, not a standard disclosure process.

Muralidhar also pointed to subsequent emails in which Pathak allegedly proposed charging $65,000 for an attack-surface analysis and $3,000 per month for maintenance. He argued that the combination of downloading thousands of customer files, referencing publication, and demanding payment supported the prosecution’s case and could not be dismissed at the threshold. “This is not an ordinary person you're dealing with,” he submitted.

Court’s Key Observations

The bench focused on the alleged downloading of 8,000 files and questioned whether such a volume was necessary to demonstrate a security weakness. The judges drew a clear distinction between notifying a company that its system is vulnerable and actually removing sensitive information from its database.

“The moment sensitive personal information is removed from a company's database, the privacy interests of the individuals whose information is contained in that data are implicated,” the Court observed. This statement reflects a growing judicial concern over data privacy, especially after the landmark Puttaswamy judgment recognising the right to privacy as a fundamental right under Article 21.

The Court also questioned whether a cybersecurity researcher could independently access and download data merely because the objective was to demonstrate a vulnerability. It noted that even if a person believes another entity is acting improperly, that does not authorise the person to obtain private information and use its possession as leverage.

Ultimately, the bench held that the competing accounts—Pathak’s claim of bona fide research versus Star Health’s allegations of extortion and data theft—involved factual questions that must be assessed during trial. “In the facts and circumstances of the case, we are not inclined to entertain these Special Leave Petitions. The same stand dismissed with liberty to the petitioner to raise all the contentions before the Trial Court at an appropriate stage,” the order stated.

Legal Analysis: Limits of Section 482 CrPC

The Supreme Court’s refusal to quash the proceedings reaffirms the limited scope of Section 482 CrPC. The inherent power to prevent abuse of process is not meant to adjudicate disputed facts. As the bench indicated, issues such as whether Pathak’s conduct was bona fide, whether downloading data was necessary, and whether his communications amounted to extortion require evidence and cross-examination.

This approach is consistent with the principle laid down in State of Haryana v. Bhajan Lal (1992), where the Supreme Court held that FIRs can be quashed only in exceptional circumstances where the allegations do not disclose any offence. Here, the allegations—unauthorised access, downloading, and pressure through publication threats—prima facie disclose offences under the Information Technology Act, 2000, and possibly the Indian Penal Code.

The case also highlights the tension between cybersecurity research and data protection. While responsible disclosure is encouraged, the law does not grant a blanket immunity to researchers who access and remove personal data without authorisation. The upcoming Digital Personal Data Protection Act, 2023, may provide clearer guidelines, but currently, the legal framework remains case-specific.

Impact on Legal Practice and Cybersecurity

For legal practitioners, this judgment serves as a reminder of the importance of factual pleadings at the investigation stage. Defence lawyers must be prepared to demonstrate not just the absence of criminal intent but also the proportionality of the researcher’s actions. The closure of the Policybazaar case may be a persuasive precedent, but each case turns on its own facts.

Cybersecurity professionals and companies should take note of the Court’s emphasis on privacy. Even well-intentioned research can attract criminal liability if personal data is removed from a system without authorisation. The safest practice is to report vulnerabilities without downloading data, or to do so only under a formal bug bounty program with clear terms.

The Supreme Court has left the door open for Pathak to prove his bona fides before the trial court. His defence will likely rely on the Policybazaar closure report and acknowledgements from other organisations. However, Star Health’s metadata records may provide forensic evidence of the extent of access, which could strengthen its case.

Conclusion

The Supreme Court’s refusal to quash the criminal proceedings against Himanshu Pathak does not prejudge his guilt or innocence. It simply recognises that the dispute requires a full trial. The case will now proceed before the XI Metropolitan Magistrate, Chennai, where the court will examine the evidence, including the emails, metadata, and the parties’ conduct.

For the legal community, this case underscores the evolving intersection of cybersecurity, data privacy, and criminal law. As digital vulnerabilities become more common, courts will increasingly be called upon to balance the interests of security researchers, companies, and individuals whose data is at stake. Until a clear statutory framework emerges, each case will likely set its own precedent.