The chief “information security” officer sold data of 31 million Indians to a Chinese hacked for just $43k
Then decided to ask for more money and that’s when the hacker exposed him.
EXCLUSIVE: Star Health is a $1.4B revenue insurance company whose CISO sold ~31 million Indians' data from salary to PAN card to a Chinese hacker for $43k.
Ever wondered how these things happen? Here's a breakdown of the events "allegedly" with video proof.
1. Amarjeet Khanuja, CISO of Star Health, reaches out to xenZen through a referral from denol on encrypted chat app Tox on July 6, 2024.
2. xenZen says yes and they negotiate and land on $28k for customer data on Monero (crypto). CISO doesn't know Bitcoin is a bad idea for this nor has ever used escrow.
3. CISO sends hacker login credential and an API endpoint w/details on their proton mail. Hacker sends money and gets it.
4. On July 20, CISO says I can also give you all the claims data. They agree on $15k and repeat the above.
5. Five days later, hacker says his access was revoked and CISO says "You've taken 5TB and I want $150k now because senior management wants a cut."
6. Hacker asks for a refund and gives final warning.
7. xenZen posted a sale listing on BreachForums for diplomatic passports of India (unrelated).
8. Sep 25 is when the starhealthleak website drops with 2 Telegram bots for customer and claims data.
From private sources, xenZen says he's bought and sold data from Indian companies before. Attached is video evidence which is unlikely to be spoofed.
The media did not care until I posted about it yesterday. Star Health responded by legal threats against Telegram and Cloudflare and a forensic investigation.
People in power in India (and perhaps elsewhere) will sell your data in a heartbeat. Why? No one seems to care.