Skip to content
Common knowledge that data of Indians is traded on dark web: Supreme Court

Common knowledge that data of Indians is traded on dark web: Supreme Court

Barandbench • October 1, 2026

It is common knowledge that personal data of Indians is traded on the dark web, the Supreme Court said on Thursday.

A Bench of Justices Joymalya Bagchi and V Mohana commented on persisting cyber threats to personal data stored on computer and online ecosystem.

The Court was hearing a plea moved by cybersecurity researcher Himanshu Pathak regarding alleged data vulnerabilities in the systems of Star Health and Allied Insurance Company.

Representing Star Health, Senior Advocate S Muralidhar today assured the Court that the data being secured by the insurance company is secure, contrary to Pathak’s apprehensions.

“ We have taken extraordinary security measures. Your Lordships will be quite astonished how many layers of security we have built. We do continuous monitoring now , ” Muralidhar said.

“ But it is common knowledge that data of Indians is being traded on the dark web ,” pointed out Justice Bagchi.

“ Dark web is something beyond the control of anyone, with the greatest respect. Just because there is a dark web, we cannot be complicit,” replied Muralidhar.

Advocate Prashant Bhushan appeared for Pathak.

After the Madras High Court dismissed his plea for a probe into the matter, he approached the Supreme Court for relief.

“ After the leak of 2024, now this is an insider who has given access to the entire data. He (Pathak) says he can send data of government employees, Supreme Court judges, everybody. How can a company like this be allowed to get away without even an investigation? Even in September this year, a hacker is saying that he received all the data from their own employee,” Bhushan told the Court today.

The counsel also refuted Star Health’s allegations that Pathak had raised these issues in a bid to extort money.

The Court, however, expressed reservations Pathak's plea and his bonafides.

Justice Bagchi remarked that hacking into a system to expose its vulnerabilities may not be the right way to go.

“ We are not hacking. We are finding vulnerabilities in these systems on the basis of which anybody can access the data, ” Bhushan clarified.

“ Like a locksmith who comes into a house, breaks into the house and then says there is a security vulnerability?” asked Justice Bagchi

“ No. Everyone is getting in. That's what they pointed out to them… I have highlighted the security vulnerability. This very company was reportedly hacked in 2024,” replied Bhushan.

Bhushan went on to suggest that if the Court is unsure of Pathak’s motives, it can still examine the larger issues raised by appointing an amicus curiae for assistance, without Pathak being a formal party to the case. Bhushan asserted that Pathak’s work was well-intentioned.

“ We have done it (checking data vulnerabilities) for six government organisations. Every time we pointed out that this was a vulnerability in their system, they had to fix that vulnerability. We are rendering valuable public service,” he said.

The Court, however, continued to express reservations whether it should entertain a petition filed by Pathak in the matter.

It suggested that Pathak could instead raise his concerns before a civil court presently dealing with proceedings initiated by Star Health against the cybersecurity researcher.

“We don't want this to become the vehicle of the public interest. I request you to withdraw this petition, without prejudice to your rights and contentions to canvass these issues in the pending proceedings,” Justice Bagchi said.

Bhushan, in turn, again urged the Court to examine the larger issues raised by Pathak one way or another.

“ What I am requesting is that because of the seriousness of the matter, the public interest aspect be kept open. This is so serious. Appoint an amicus. Let Dr Muralidhar be the amicus, or somebody like him,” Bhushan submitted.

He went on to re-assert that Pathak did not “hack” any Star Health data; rather such data was accessed easily because of poor safeguards.

“ I did go accidentally. When you type somebody else's name, his data also comes up,” he said.

Muralidhar reiterated that Star Health has “completely foolproof” cybersecurity measures in place.

“ On a daily basis they monitor, not themselves, but through external independent CERT-In-certified agencies. They rotate them. The same agency doesn't continue beyond six months ,” he added.

Justice Bagchi, in turn, noted that such security measures need to be constantly updated.

“ The very software or technology which is used to access it itself mutates. Therefore, the firewalls and guardrails also need to be continuously ,” he said.

“ Correct. They use different audit agencies precisely for this reason ,” replied Muralidhar.

The case will be heard further on October 7.

#SupremeCourt flags the "public interest" involved in protecting vast repositories of personal data while hearing cybersecurity researcher Himanshu Pathak's plea concerning alleged data vulnerabilities. Justice Joymalya Bagchi: "There are two aspects... One is the fact that he… pic.twitter.com/t7EZP0lCMa — Bar and Bench (@barandbench) October 1, 2026

#SupremeCourt flags the "public interest" involved in protecting vast repositories of personal data while hearing cybersecurity researcher Himanshu Pathak's plea concerning alleged data vulnerabilities. Justice Joymalya Bagchi: "There are two aspects... One is the fact that he… pic.twitter.com/t7EZP0lCMa

Extracted Entities