Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Lucid Bots raises $20 million to meet demand for its window-washing drones

Waymo’s ridership surge in a graph

David Sachs is done as AI czar — here’s what he’s doing instead

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    David Sachs is done as AI czar — here’s what he’s doing instead

    28 March 2026

    Now you can transfer your conversations and personal information from other chatbots directly to Gemini

    27 March 2026

    Anthropic wins injunction against Trump administration over Defense Department saga

    27 March 2026

    A ‘pound of flesh’ from data centers: a senator’s response to AI job losses

    26 March 2026

    Mercor competitor Deccan AI raises $25 million, India experts report

    26 March 2026
  • Apps

    Google launches Search Live worldwide

    28 March 2026

    Google Translate’s real-time headset translation feature is expanding to iOS and more countries

    27 March 2026

    Mastodon is making its decentralized social network easier to use with its latest update

    27 March 2026

    WhatsApp can now design AI-generated replies based on your conversations

    26 March 2026

    Apple overhauls its app developer platform with 100 new metrics, more tools

    26 March 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Doss raises $55 million for AI inventory management that connects to ERP

    24 March 2026

    Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

    23 March 2026

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026

    Nominations for the Startup Battlefield 200 are still open

    19 March 2026

    Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

    17 March 2026
  • Hardware

    Memory chip giant SK hynix could help end ‘RAMmageddon’ with successful US IPO

    27 March 2026

    Arm releases the first in-house chip in its 35-year history

    24 March 2026

    Ultrahuman boosts US push with Ring Pro as Oura tightens its grip

    24 March 2026

    Amazon is working on a new smartphone with Alexa at its core, the report says

    20 March 2026

    CEO Carl Pei says nothing about smartphone apps disappearing as they’re replaced by artificial intelligence agents

    18 March 2026
  • Media & Entertainment

    Netflix confirms it’s raising prices again

    27 March 2026

    Spotify’s new SongDNA feature maps how your favorite songs are connected

    26 March 2026

    Roku’s Howdy $3 subscription service launches on Prime Video

    25 March 2026

    Apple Music partners with Ticketmaster to boost concert discovery

    25 March 2026

    Google TV’s new Gemini features keep fans updated on sports teams and more

    24 March 2026
  • Security

    Iranian hackers claim to have breached FBI Director Kash Patel’s personal email account

    27 March 2026

    A major hacking tool has leaked online, putting millions of iPhones at risk. Here’s what you need to know.

    27 March 2026

    Apple made strides with iOS 26 security, but leaked hacking tools still leave millions exposed to spyware attacks

    26 March 2026

    Convicted spyware boss hints Greek government was behind dozens of phone hacks

    26 March 2026

    Someone has publicly leaked an exploit kit that can hack millions of iPhones

    25 March 2026
  • Startups

    Lucid Bots raises $20 million to meet demand for its window-washing drones

    28 March 2026

    Why Hiring the Weird Works

    27 March 2026

    Silicon Valley’s two biggest dramas have crossed paths: LiteLLM and Delve

    27 March 2026

    Conntour Raises $7M From General Catalyst, YC To Build AI Search Engine For Security Video Systems

    26 March 2026

    Delve Made Security Compliant on LiteLLM, an AI Project Hit by Malware

    26 March 2026
  • Transportation

    Waymo’s ridership surge in a graph

    28 March 2026

    Sony and Honda abandon their joint EV project

    27 March 2026

    A little-known Croatian startup is coming to the robotaxi market with the help of Uber

    27 March 2026

    A little-known Croatian startup is coming to the robotaxi market with the help of Uber

    26 March 2026

    Harbinger’s next product will be hybrid emergency vehicles

    25 March 2026
  • Venture

    16 of the most interesting startups from the YC W26 Demo Day

    27 March 2026

    BKR Capital Raises $14.5M (So Far) to Invest in Black Founders

    26 March 2026

    Driving GLP-1 Boom, VITL Raises $7.5M to Repair Cash Clinic Prescribing

    26 March 2026

    Arinna raises $4 million to solve the space energy problem

    25 March 2026

    Accel, Prosus select six ‘off-the-map’ startups for inaugural India team

    25 March 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»The Indian pharmacy chain giant exposed customer data and internal systems
Security

The Indian pharmacy chain giant exposed customer data and internal systems

techtost.comBy techtost.com14 February 202603 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
The Indian Pharmacy Chain Giant Exposed Customer Data And Internal
Share
Facebook Twitter LinkedIn Pinterest Email

A security flaw at one of India’s largest pharmacy chains allowed outsiders to gain full administrative control of its platform, exposing customer order data and sensitive drug control functions, TechCrunch has learned exclusively.

The issue affected DavaIndia Pharmacy, the pharmacy division of Zota Healthcare, which operates a large network of retail stores across India. Security researcher Eaton Zveare told TechCrunch that he discovered the flaw after spotting insecure “super admin” APIs on DavaIndia’s website and sharing private information with Indian cybersecurity authorities.

The bug is now fixed and Zveare revealed his findings.

The report comes as Zota Healthcare is rapidly scaling up the retail business of DavaIndia Pharmacy. The Gujarat-based company has more than 2,300 DavaIndia stores across India, including 276 new points of sale announced in January and plans to add another 1,200 to 1,500 the next two years.

Zveare told TechCrunch that the flaw stemmed from insecure admin interfaces, which allowed unauthenticated users to create “super admin” accounts with elevated privileges.

With that level of access, an attacker could view thousands of online orders containing customer information, modify product listings and prices, create discount coupons and change settings governing whether certain drugs require a prescription, the researcher said.

Based on system timestamps, Zveare said the vulnerable administrative interfaces appeared to be live as of late 2024. The access revealed nearly 17,000 online orders and administrative controls covering 883 stores, he said, allowing for changes to product pricing, prescription requirements and promotional discounts. Zveare said the access allowed modifications to website content that could have been used to distort or disrupt.

Pharmacy order data can be particularly sensitive as it may reveal information about an individual’s health status, medications or other private purchases. Exposure of such data, even without evidence of misuse, carries increased risks to patient privacy and security compared to other consumer information.

“Customer information was linked to their orders,” Zveare said. “This includes name, phone numbers, email IDs, postal addresses, total amount paid and products purchased. As this is a pharmacy, the products purchased could be considered private and even embarrassing to some people.”

Zveare said he reported the issue to CERT-In, India’s national cyber emergency response agency, in August 2025. The vulnerability was patched within weeks, though confirmation from the company took longer and was given to cyber authorities in late November, he said.

Sujit Paul, CEO of Zota Healthcare, did not respond to emails sent by TechCrunch last month. The researcher said there was no indication that the flaw had been exploited before it was patched.

chain customer cyber security data data report DavaIndia Exclusive exposed giant Indian Internal pharmacy systems Zota Healthcare
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleScore, the dating app for people with good credit, is back
Next Article YouTube introduces an AI playlist maker for Premium users
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Waymo’s ridership surge in a graph

28 March 2026

Memory chip giant SK hynix could help end ‘RAMmageddon’ with successful US IPO

27 March 2026

Iranian hackers claim to have breached FBI Director Kash Patel’s personal email account

27 March 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Lucid Bots raises $20 million to meet demand for its window-washing drones

28 March 2026

Waymo’s ridership surge in a graph

28 March 2026

David Sachs is done as AI czar — here’s what he’s doing instead

28 March 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Doss raises $55 million for AI inventory management that connects to ERP

24 March 2026

Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

23 March 2026

Amid legal turmoil, Kalshi is temporarily banned in Nevada

20 March 2026
Startups

Lucid Bots raises $20 million to meet demand for its window-washing drones

Why Hiring the Weird Works

Silicon Valley’s two biggest dramas have crossed paths: LiteLLM and Delve

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.