🏠 News Empire
tech

Supreme Court grants interim bail to cyber researcher in data access case

Published on: 06 Aug 2026, 07:16 PM
Supreme Court grants interim bail to cyber researcher in data access case

The Supreme Court on Thursday granted interim bail to Himanshu Pathak, a cyber-security researcher accused by the Chennai Police of unauthorised access to computer networks and extraction of insurance-related data.

A Bench of the Supreme Court led by Justice Surya Kant issued notice to the State of Tamil Nadu, returnable on September 18. The court also directed the State to furnish details of any similar cases or criminal antecedents pending or registered against the petitioner.

Pathak had moved the apex court after the Madras High Court, on July 3, rejected his plea to quash the chargesheet filed against him by the CCB Cyber Crime Police Station for offences under Sections 66 (punishment for accessing computer systems or networks without permission) and 43(b) (extraction of data from a computer) of the Information Technology Act.

The special leave petition filed by Pathak also named Star Health and Allied Insurance Co. Ltd as a respondent. He was represented by advocates Prashant Bhushan and Cheryl Dsouza, while advocate B. Karunakaran accepted notice on behalf of the State. Advocate Shloka Narayanan accepted notice for the insurance company.

The court asked the State to furnish details of similar cases or criminal antecedents, if any, against the petitioner. It directed Pathak to appear before the Saidapet Magistrate court concerned to furnish bail bonds for interim bail, and allowed him to apply for exemption from personal appearance.

The petition argued that the case raises important questions concerning the threshold at which criminal prosecution under Sections 43(b) and 66 may legitimately be permitted to proceed, and the duty of the High Court to interdict prosecutions that fail to disclose the essential ingredients of the alleged offence.

According to the petitioner, while accessing the insurance records of his father's policy issued by the company in 2022, he discovered that its digital infrastructure exposed complete policyholder records through an unsecured legacy API that responded to unauthenticated requests upon alteration of the policy number. He attributed this to a pre-existing vulnerability in the company's own legacy application and said he had communicated with CERT-In, the Indian Computer Emergency Response Team.

The prosecution version, as recorded in the petition, alleges that Pathak deliberately accessed the company's computer resources without authorisation, extracted approximately 8,000 policyholder records, demanded annual consultancy charges of USD 65,000 and monthly maintenance charges of USD 3,000, and threatened to leak confidential customer information.

Latest in Tech 10
→ View All Tech News