India

Parker said he posed as a potential buyer on a online hacker forum where a user under the alias xenZen said they made the chatbots and possessed 7.24 terabytes of data related to over 31 million Star Health customers.5 min read Last Updated : Sep 20 2024 | 10:39 AM IST Stolen customer data including medical reports from India's biggest health insurer, Star Health, is publicly accessible via chatbots on Telegram, just weeks after Telegram's founder was accused of allowing the messenger app to facilitate crime. The purported creator of the chatbots told a security researcher, who alerted Reuters to the issue, that private details of millions of people were for sale and that samples could be viewed by asking the chatbots to divulge.  Star Health and Allied Insurance, whose market capitalization exceeds $4 billion, in a statement to Reuters said it has reported alleged unauthorized data access to local authorities.

It said an initial assessment showed "no widespread compromise" and that "sensitive customer data remains secure".   Using the chatbots, Reuters was able to download policy and claims documents featuring names, phone numbers, addresses, tax details, copies of ID cards, test results and medical diagnoses.  The ability for users to create chatbots is widely credited with helping Dubai-based Telegram become one of the world's biggest messenger apps with 900 million active monthly users.  However, the arrest of Russian-born founder Pavel Durov in France last month has increased scrutiny of Telegram's content moderation and features open to abuse for criminal ends.

Durov and Telegram denied wrongdoing and are addressing the criticism.  The use of Telegram chatbots to sell stolen data demonstrates the difficulty the app has in preventing nefarious agents taking advantage of its technology and highlights the challenges Indian companies face in keeping their data safe.  The Star Health chatbots feature a welcome message stating they are "by xenZen" and have been operational since at least Aug.

6, said UK-based security researcher Jason Parker.  Parker said he posed as a potential buyer on a online hacker forum where a user under the alias xenZen said they made the chatbots and possessed 7.24 terabytes of data related to over 31 million Star Health customers.

The data is free via the chatbot on a random, piecemeal basis, but for sale in bulk form.  Reuters could neither independently verify xenZen's claims nor ascertain how the chatbot creator obtained the data.

In an email to Reuters, xenZen said they were in discussions with buyers without disclosing who or why they were interested. Taken down  In testing the bots, Reuters downloaded more than 1,500 files with some documents dated as recently as July 2024. "If this bot gets taken down watch out and another one will be made available in few hours," the welcome message read.  The chatbots were later marked "SCAM" with a stock warning that users had reported them as suspect.

Reuters shared details of the chatbots with Telegram on Sept.

16 and within 24 hours spokesperson Remi Vaughn said they had been "taken down" and asked to be informed should more appear.  "The sharing of private information on Telegram is expressly forbidden and is removed whenever it is found.

Moderators use a combination of proactive monitoring, AI tools and user reports to remove millions of pieces of harmful content each day." New chatbots have since appeared offering Star Health data.  Star Health said an unidentified person contacted it on Aug.  13 claiming to have access to some of its data.

The insurer reported the matter to the cybercrime department of its home state of Tamil Nadu and federal cyber security agency CERT-In.  "The unauthorized acquisition and dissemination of customer data is illegal, and we are actively working with law enforcement to address this criminal activity.

Star Health assures its customers and partners that their privacy is of paramount importance to us," it said in its statement.  In an Aug.

14 stock exchange filing, Star Health, India's biggest player among standalone health insurance providers, said it was investigating an alleged breach of "a few claims data".  Representatives for CERT-In and the Tamil Nadu cybercrime department did not respond to emailed requests for comment.Unaware Telegram allows individuals or organizations to store and share large amounts of data behind anonymous accounts.

It also lets them create customizable chatbots which automatically provide content and features based on user requests.  Two chatbots distribute Star Health data.

One offers claim documents in PDF format.

The other allows users to request up to 20 samples from 31.2 million datasets with a single click giving details including policy number, name and even body mass index. Among documents disclosed to Reuters were records related to the treatment of the one-year-old daughter of policyholder Sandeep TS at a hospital in the southern state of Kerala.

The records included diagnosis, blood test results, medical history and a bill of nearly Rs 15,000 ($179).  "It sounds concerning.

Do you know how this can affect me?" said Sandeep, confirming the documents' authenticity.

He said Star Health had not notified him of any data leak.  The chatbot also leaked a claim last year by policyholder Pankaj Subhash Malhotra which included ultrasound imaging test results, details of illness and copies of federal tax account and national ID cards.

He also confirmed the documents were genuine and said he was not made aware of any security breach.  The Star Health chatbots are part of a broader trend of hackers using such methods to sell stolen data.

Of five million people whose data was sold via chatbots, India represented the largest number of victims at 12%, showed the latest survey on the epidemic conducted by NordVPN at the end of 2022.  "The fact that sensitive data is available via Telegram is natural, because Telegram is an easy-to-use storefront," said NordVPN cybersecurity expert Adrianus Warmenhoven.

"Telegram has become an easier to use method for criminals to interact." (Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)First Published: Sep 20 2024 | 10:28 AMIST





Unlimited Portal Access + Monthly Magazine - 12 issues-Publication from Jan 2021


Buy Our Merchandise (Peace Series)

 


Contribute US to Start Broadcasting



It's Voluntary! Take care of your Family, Friends and People around You First and later think about us. Its Fine if you dont wish to contribute and if you wish to contribute then think about the Homeless first and Feed them. We can survive with your wishes too :-). You can Buy our Merchandise too which are of the finest quality.


STRIPE


[India] - Forex reserves rise for 5th week, struck record high of $689.46 bn: RBI information


Wave Group prepares launch of 9,000 flats in 'Wave City' task at Ghaziabad


DPIIT refers complaint against quick e-commerce players to CCI: Report


Moglix to invest $50 million in Credlix for expansion in USA, Mexico


Apple Releases iOS 18.1 Public Beta with Waitlist for Apple Intelligence


[India] - Apple iPhone 16 series sale begins in India: Check costs and bank offers


[India] - PhysicsWallah raises $210 mn; valuation leaps 2.5 times to $2.8 bn


NBFC Aye Finance raises $30 million in series G round led by ABC Impact


[India] - CARE Ratings downgrades IIFL Finance's long-term instruments to AA-


[India] - Axis Capital to explore legal treatments against Sebi's ban on debt sector


[India] - TCS announces launch of brand-new delivery centre in Poland, aims to broaden ops


[India] - TCS broadens operations in Poland, aims to double labor force in a year


Edtech startup Physics Wallah's valuation crosses $2.8 bn with new funding


Apple Releases iOS 18.1 Public Beta with Waitlist for Apple Intelligence


[India] - Hacker uses Telegram chatbots to leakage information of Indian insurer Star Health


[India] - Apple iPhone 16 series sale begins in India: Check prices and bank offers


[India] - SpiceJet's share sale most likely to tempt Tata Mutual Fund to name a few


Govt approves sale of FSNL to Japan's Konoike Transport for Rs 320 cr


[India] - Banks to play crucial role in making India established nation: FM Sitharaman


[India] - RBI lifts limitations imposed on IIFL Finance's gold loan organization


[India] - Cisco's second 2024 layoff: 5,600 jobs cut, shifts focus to AI growth


[India] - Banks to play significant function in making India established by 2047: FM Sitharaman


[India] - Binance separates itself from any liabilities days after WazirX cyber attack


[India] - Samsung sues Indian labour union over strike that interrupted production


[India] - Motilal Oswal Foundation pledges Rs 130 cr to IIT-B for scholastic upgrade


With iPhone 16 series, Apple makes it easy to eliminate and replace components


[India] - Impact of US Fed rate cut might be muted in India: CEA Nageswaran


[India] - HDFC Bank most likely to close $1 billion loan sale this month: Report


[India] - India on way to becoming third-largest economy by FY31: S P Global report


[India] - Govt probing claims by EY worker's mom about company's work culture


[India] - Morgan Stanley protects Rs 2,122 cr office lease for 16 floors in Mumbai


[India] - Bengaluru's millionaire population skyrockets by 120% over last years: Report


[India] - Analog Devices, Tata Group sign pact to make semiconductors in India


[India] - Bharti Airtel becomes 4th noted business to cross Rs 10 trillion market cap


SpiceJet gets great reaction for Rs 3k cr worth share sale, oversubscribed


[India] - Bengaluru's millionaire population skyrockets by 120% over last years: Report


Hero MotoCorp's e-scooters to debut in the UK and EU markets in 2025


[India] - Analog Devices, Tata Group indication pact to make semiconductors in India


Pokemon sues adventure game 'Palworld' producer for patent infringement


[India] - Bharti Airtel becomes 4th noted company to cross Rs 10 trillion market cap


Microsoft prez alerts of possible meddling in final 48 hours of US elections


X skirts Brazil restriction and go back to some users with change to server gain access to


Walkie-talkie surges in Lebanon eliminate at least 14, hurt 450 others


US Fed slashes interest rates by 50 bps for the first time since 2020


SpiceJet gets excellent action for Rs 3k cr worth share sale, oversubscribed


Google checks out RCS encryption for Chats in between Android and iPhone users


[India] - AI-led dating platform Schmooze raises $4 million series A round


[India] - NBFCs throng bond mkt to fund celebration credit need as bank financing slows


Not paid GST, TDS, and PF dues of Rs 427 crore since 2020: SpiceJet


Arvind Kejriwal resigns as Delhi Chief Minister, Atishi set to take over


[India] - Reckitt Benckiser starts talks on $7.9 billion homecare assets sale


Samsung begins pre-reserve for upcoming Galaxy Tab S10 series in India


Belkin launches Apple-certified Auto-Tracking Stand Pro for MagSafe iPhones


LIC appoints Infosys to construct NextGen platform as part of DIVE programme


[India] - Torrent Power dedicates Rs 64,000 crore investment for green tasks


Air traffic soars as more passengers opt for direct flights to from India


[India] - Kenya awards $1.3 bn transmission offer to Adani amidst airport lease demonstrations


Rifle poking from bushes: How Donald Trump left newest assassination quote


Here's what India needs to accomplish its semiconductor ambitions


Shipbuilders from Japan, Korea keen to invest here: Sarbananda Sonowal


US lenders counter Byju's claim, says edtech has to repay full $1.2 bn


Piyush Goyal to launch Bharat Startup Knowledge Access Registry on Monday


Inside Elon Musk's mushrooming security device in Tesla factories


[India] - RBI plans to revamp currency management infra to accommodate future money needs


Reliance broadens trading area by 50% for non-food general merchandise


[India] - SOM Distilleries debuts in K'taka with Woodpecker beer, eyes 1,600 cr sales


Kejriwal to resign as CM in 2 days, requires public to offer decision


Development of tribals, poor, youth, women our priority: PM Modi in J'khand


[India] - FPIs inject Rs 27,856 cr in equities in Sept on US rate cut expectations


USFDA cites producing lapses at Zydus Lifesciences' Gujarat plant


[India] - Water purifier maker Livpure eying over 1 mn memberships within 4 years


Epsilon Advanced Materials plans Rs 9,000 cr anode facility in K'taka: MD


Mcap of 9 of top-10 most valued firms jump Rs 2 trn; Bharti Airtel sparkles


PM Modi to visit Jharkhand today to flag off 6 new Vande Bharat trains


Nitin Gadkari says he was offered support for PM's post, but he declined


[India] - Sebi exempts SHPL from making open offer for SpiceJet investors


OIL to invest Rs 25,000 cr in clean energy for net zero emissions by 2040


Congress fires fresh salvo against Sebi Chairperson Madhabi Puri Buch


[India] - Mcap of 9 of top-10 most valued firms jump Rs 2 trn; Bharti Airtel sparkles


PM Modi to go to Jharkhand today to flag off 6 new Vande Bharat trains


Encounter with terrorists underway in Kashmir's Poonch; area cordoned off


Investors to focus on US Fed interest rate decision this week: Analysts


Nitin Gadkari says he was used support for PM's post, but he declined


[India] - Sebi exempts SHPL from making open offer for SpiceJet investors


[India] - OIL to invest Rs 25,000 cr in tidy energy for net no emissions by 2040


Oberoi Grp family dispute: Delhi HC injuncts shares held by late PRS Oberoi


NCLT recalls order on Zee-Sony merger, allows withdrawal of scheme


OIL aims to drill 75-plus wells in FY25 using more rigs, newer tech: CMD


[India] - Govt raises import tax on crude, improved edible oils to support farmers


[India] - CCI finds Samsung, Xiaomi conspiring with Amazon, Flipkart: Report


[India] - Congress fires fresh salvo versus Sebi Chairperson Madhabi Puri Buch


LG Electronics picks banks for $1.5 billion listing of Indian unit


[India] - Byju's bankruptcy judgment in US comes as a surprise for Indian authorities


[India] - IPO-bound Ecom Express utilized inaccurate numbers in DRHP, says Delhivery


[India] - Short-sellers might target banks with big CRE exposure: RBI governor Das


[India] - E-commerce firm Flipkart equips sellers with tools ahead of flagship event


Majority of Adani group stocks settle lower, Adani Power down nearly 3%


[India] - Byju's bankruptcy ruling in US comes as a surprise for Indian official


Investors authorize Rs 3,000 crore fund raising plan, says SpiceJet


[India] - IPO-bound Ecom Express used inaccurate numbers in DRHP, says Delhivery


[India] - After 2 years, Ford takes road back to India to make e-cars for export


[India] - Short-sellers may target banks with big CRE direct exposure: RBI governor Das


[India] - E-commerce company Flipkart gears up sellers with tools ahead of flagship event


Bulk of Adani group stocks settle lower, Adani Power down almost 3%


[India] - Akums Drugs gets patent for formula to handle sickle cell disease


[India] - Zomato teams up with IRCTC to use food delivery service on trains


Our focus is on being a future all set business, says Rites CMD Mithal


[India] - Realme P2 Pro 5G, Pad 2 Lite launched in India: Check price, specifications and more


[India] - Akums Drugs gets patent for formula to manage sickle cell illness


[India] - Zomato teams up with IRCTC to provide food delivery service on trains


Arvind Kejriwal gets bail, but SC split on legality of CBI's arrest


Govt decides to rename Port Blair as Sri Vijaya Puram, says Amit Shah


Sebi chairperson Madhabi Puri Buch rubbishes Congress allegations


Our focus is on being a future prepared company, says Rites CMD Mithal


iPhone 16 series now available for pre-order in India, sale begins Sept 20


[India] - Realme P2 Pro 5G, Pad 2 Lite introduced in India: Check cost, specifications and more


[India] - Tamil Nadu labour minister to satisfy Samsung officials to fix strike


Kalpataru Projects International bags orders worth Rs 2,774 crore


[India] - NaBFID should end up being self-sustainable, not rely on govt: RBI dy guv


As regulators get hard, Big Tech's simple ride is pertaining to an end


[India] - Sebi considers new stricter guidelines to suppress risks as small IPOs boom


HDFC in talks with int'l banks to offload $1 bn in loans to cut credit book


[India] - Paytm to focus on core biz; deliver success quickly: CEO Sharma


[India] - Durex makes India condom push for females, rural consumers with lubes, advertisements


[India] - NITI Aayog group proposes different law to deal with public health crises


SpaceX's competing AST SpaceMobile soars 1,300%; now comes the satellite launch


Google's AI model deals with EU analysis from guard dog over personal privacy rules


Highest frequency of road crash deaths from 9 pm to 2 am, 89% men: Report


EVs get Rs 14k crore double shot: Boost for ambulances, buses, trucks


[India] - Samsung plans global job cuts of approximately 30% in some departments: Report


SpiceJet to pay elderly couple complete refund for flight cancelled in Covid


Investors demanded sustainability over rapid growth: GoMechanic's Kakkar


Tata Steel, UK govt indication GBP 500 mn grant agreement for Port Talbot job


Vedanta Resources gets $900 mn via first dollar bond issue to prepay loans


[India] - Sebi tweaks margin trading centers' structure to relieve collateral burden


UK gets improved terms for 2,500 workers as it recommits to Tata Steel deal


IndiGo pays lowered Rs 70 lakh fine to BCAS over Mumbai airport occurrence


[India] - CCI offers nod to Dixon Technologies to acquire stake in Aditya Infotech


[India] - PhonePe, Liquid Group tie up to expand UPI QR payment service in Singapore


IndiGo pays reduced Rs 70 lakh fine to BCAS over Mumbai airport event


[India] - CCI provides nod to Dixon Technologies to acquire stake in Aditya Infotech


[India] - PhonePe, Liquid Group bind to expand UPI QR payment service in Singapore





53