Skip to content
Security Breach Exposes Customer Data at DavaIndia Pharmacy in India

Security Breach Exposes Customer Data at DavaIndia Pharmacy in India

Mezha February 14, 2026

A security breach at one of India’s largest pharmacy networks allowed external parties to gain full admin access to the DavaIndia Pharmacy platform, exposing customer data and sensitive medicine-control features, TechCrunch reports in an exclusive piece.

This concerns DavaIndia Pharmacy, the pharmacy arm of Zota Healthcare, which has a wide network of retail outlets across India. Security researcher Eiton Zveare told TechCrunch that he discovered the vulnerability after identifying unsecured “super admin” interfaces on the DavaIndia site and privately passed the details to the corresponding cybersecurity bodies in India.

The issue was fixed, and Zveare published his findings regarding the incident.

The breach occurred amid the rapid expansion of DavaIndia Pharmacy’s retail business. The Gujarat-based company operates over 2,300 stores across India, including 276 new outlets opened in January, and plans to add between 1,200 and 1,500 outlets over the two years.

According to Zveare, the vulnerability lay in unprotected administrative interfaces that allowed unauthorized users to create “super admin” accounts with high privileges.

With such a level of access, the attacker could view thousands of online orders with customer data, modify product listings and prices, create discount coupons, and alter settings that determined whether a prescription was required for certain medicines, – the researcher explained.

Based on system timestamps, the vulnerable administrative interfaces were likely active since late 2024. The breach affected nearly 17,000 online orders and management functions in 883 stores, allowing price changes, prescription requirements, and promotional discounts. It was also noted that the site content could be edited, which could be used for defacement or disrupting the operation of the systems.

Pharmacy-order data is highly sensitive because it can reveal information a person’s health status, medications, or private purchases. The exposure of such information, even without evidence of misuse, carries heightened privacy and patient-safety risks compared with other data.

“Customer information was tied to their orders.”

“This includes names, phone numbers, email addresses, mailing addresses, the total payment amount and purchased products. Since this is a pharmacy, the purchased items may be private and even embarrassing for some people.”

Zveare said the issue was reported to CERT-In, India’s national cybersecurity agency, in August 2025. The vulnerability was fixed within a few weeks, but confirmation from the company to cyber outlets arrived later – in late November 2025.

Sujit Paul, the CEO of Zota Healthcare, did not respond to TechCrunch’s requests last month. The researcher asserted that there were no signs of the vulnerability being exploited before it was fixed.

Extracted Entities

Attack Types (1)

Countries (1)

Industries (2)