
A significant security breach in one of India's leading pharmacy chains has granted unauthorized individuals complete administrative access to its systems, compromising customer order details and sensitive pharmaceutical functionalities. This incident involves DavaIndia Pharmacy, a branch of Zota Healthcare, which boasts an extensive network of retail outlets throughout the country. Security expert Eaton Zveare uncovered the vulnerability by identifying insecure 'super admin' application programming interfaces on DavaIndia’s website. He subsequently alerted Indian cybersecurity authorities about the issue in a private communication. Fortunately, the flaw has since been addressed, and Zveare has shared his findings publicly. As Zota Healthcare aggressively expands DavaIndia’s retail operations, this breach raises serious concerns. The company, headquartered in Gujarat, currently operates over 2,300 DavaIndia locations—including 276 new stores launched in January—and plans to add up to 1,500 more in the next two years. According to Zveare, the security flaw arose from unprotected admin interfaces that allowed unauthorized users to create 'super admin' accounts. With such access, an attacker could potentially view a vast number of online orders containing sensitive customer information, adjust product listings and prices, issue discount coupons, and modify settings related to prescription requirements for certain medications. The researcher noted that the vulnerable interfaces had been active since late 2024, exposing nearly 17,000 online orders and administrative controls across 883 stores. This level of access not only allowed for price changes and adjustments to prescription policies but also enabled edits to website content, which could lead to defacement or service disruptions. Pharmacy order information is particularly sensitive, as it can disclose individuals' health conditions and private purchases. Even without evidence of misuse, such exposure poses significant privacy and safety risks to patients compared to other consumer data. Zveare emphasized, "Customer information was linked to their orders, including names, phone numbers, email addresses, mailing addresses, total amounts paid, and the products purchased. Given the nature of a pharmacy, the purchased items could be considered private or even embarrassing." Zveare first reported the vulnerability to CERT-In, India's cybersecurity emergency response agency, in August 2025. Although the issue was resolved within weeks, it took longer for the company to confirm the fix, with the update reaching cyber authorities by late November. In the meantime, Zota Healthcare's CEO, Sujit Paul, has yet to respond to inquiries regarding the breach, and Zveare stated there is no indication that the vulnerability was exploited prior to its resolution.
As generative artificial intelligence continues to rise, uncertainty looms for the incoming Gen Z workforce. Leaders fro...
Business Insider | Jul 26, 2026, 10:15Artificial Intelligence (AI) is transforming our daily experiences, permeating various aspects of technology, including ...
Business Today | Jul 26, 2026, 07:05
Science Corp is poised to introduce a revolutionary retina chip in Europe, designed to restore partial vision for indivi...
Business Today | Jul 25, 2026, 01:00
As the demand for expertise in artificial intelligence surges, many are seeking ways to break into this dynamic field. H...
Business Insider | Jul 26, 2026, 10:10Nvidia has successfully forged a significant partnership with South Korea's SK Hynix to secure memory supplies essential...
CNBC | Jul 25, 2026, 05:15