AI Against Humanity
← Back to articles
Privacy 📅 February 14, 2026

Data Breach Risks in Indian Pharmacy Chain

A security flaw at DavaIndia Pharmacy exposed sensitive customer data, raising serious privacy and safety concerns. The incident highlights risks in digital healthcare.

A significant security vulnerability at DavaIndia Pharmacy, part of Zota Healthcare, exposed sensitive customer data and administrative controls to potential attackers. Security researcher Eaton Zveare identified the flaw, which stemmed from insecure 'super admin' application programming interfaces (APIs) that allowed unauthorized users to create high-privilege accounts. This breach compromised nearly 17,000 online orders and allowed unauthorized access to critical functions such as modifying product listings, pricing, and prescription requirements. The exposed data included personal information like names, phone numbers, and addresses, raising serious privacy and patient safety concerns. Although the vulnerability was reported to India's national cyber emergency response agency and was fixed shortly thereafter, the incident highlights the risks associated with inadequate cybersecurity measures in the rapidly expanding digital health sector. As DavaIndia continues to scale its operations, the implications of such vulnerabilities could have far-reaching effects on customer trust and safety in the healthcare industry.

Why This Matters

This article matters because it underscores the critical importance of cybersecurity in the healthcare sector, where sensitive personal data is at stake. The exposure of customer information can lead to privacy violations and undermine trust in healthcare providers. Understanding these risks is essential for consumers, policymakers, and companies to ensure that adequate protections are in place as AI and digital systems become more integrated into healthcare services.

Original Source

Indian pharmacy chain giant exposed customer data and internal systems

Read the original source at techcrunch.com ↗

Topic