Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Meta launches Instagram, Facebook and WhatsApp subscriptions, with more to follow, including AI plans

UK Visa Portal Revealed Thousands of Applicants’ Passports and Selfies — Then Invited Lawyers to Ask Us

SOND, a sleep tech startup from former Bose sleep chief, exits stealth with $7 million

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    ElevenLabs’ new music generation model can switch genres mid-track

    27 May 2026

    DuckDuckGo Installs Up 30% as Users Reject Google’s AI Search to ‘Force-Feed’ Them

    27 May 2026

    The Pope’s encyclical on artificial intelligence is not really about artificial intelligence

    25 May 2026

    Everyone is navigating real-time AI security — even Google

    25 May 2026

    I’ve tried Amazon’s Bee wearable and I’m a bit intrigued

    24 May 2026
  • Apps

    Spotify now lets you “clip” moments from your favorite podcast

    27 May 2026

    Truecaller is entering the eSIM business to diversify its revenue streams

    27 May 2026

    Universal Music Group and TikTok renew agreement to combat unauthorized AI music

    26 May 2026

    Google is pitching an ecosystem of AI agents to consumers who might not buy it

    26 May 2026

    Founded by Tony Robbins and Calm alums, The Path hopes to offer safer treatment with artificial intelligence

    25 May 2026
  • Crypto

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026
  • Fintech

    Disrupt 2026 Early Bird ticket savings expire in 3 days

    27 May 2026

    Disrupt 2026 Early Bird ticket prices end May 29

    26 May 2026

    Startup Battlefield 200 applications close before May 27 | TechCrunch

    26 May 2026

    General Catalyst just led a $63 million bet in India’s travel payments market

    21 May 2026

    Startup Battlefield 200 applications close on May 27

    21 May 2026
  • Hardware

    The Dreamie alarm clock made me stop using my phone in bed

    26 May 2026

    6 kitchen gadgets that make adult life easier

    25 May 2026

    Xreal, Google’s smart glasses partner, believes it has finally conquered this extremely difficult industry

    25 May 2026

    We tested Google’s AI glasses and they’re almost there

    23 May 2026

    Finnish phone maker HMD ropes Indian AI chatbot into new smartphone to reach local market

    22 May 2026
  • Media & Entertainment

    Meta launches Instagram, Facebook and WhatsApp subscriptions, with more to follow, including AI plans

    27 May 2026

    Spotify now lets you view narrated magazine articles as well

    26 May 2026

    Spotify launches an audiobook creation tool powered by ElevenLabs

    22 May 2026

    New York City Mayor Zohran Mamdani Takes To Twitch To Chat With New Yorkers

    21 May 2026

    Clouted wants to take the guesswork out of making short videos go viral

    21 May 2026
  • Security

    UK Visa Portal Revealed Thousands of Applicants’ Passports and Selfies — Then Invited Lawyers to Ask Us

    27 May 2026

    UK Visa portal leaked thousands of applicant passports and selfies online – and hasn’t fixed the leak

    27 May 2026

    Ghost hackers: the unsolved cybersecurity mystery

    26 May 2026

    Scammers abuse an internal Microsoft account to send spam links

    22 May 2026

    Law enforcement shuts down VPN service used by two dozen ransomware gangs

    21 May 2026
  • Startups

    SOND, a sleep tech startup from former Bose sleep chief, exits stealth with $7 million

    27 May 2026

    What we’re looking for in Startup Battlefield 2026 and how to apply in time for the May 27 deadline

    27 May 2026

    What ClickUp’s mass layoff tells us about the future of work

    25 May 2026

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws big VC interest

    24 May 2026

    This startup raised $43 million to create a hive mind for ships

    22 May 2026
  • Transportation

    FAA orders SpaceX to investigate Starship V3 booster failure

    27 May 2026

    The Trump administration is allowing Volvo to continue selling connected cars in the US

    27 May 2026

    Ferrari’s first EV is not for you

    26 May 2026

    Global EV market becomes K-shaped as US falls behind

    25 May 2026

    Tesla’s Full Self-Driving software is creeping into Europe

    25 May 2026
  • Venture

    ClickHouse triples annual revenue to $250 million, charting a path to an IPO

    27 May 2026

    The pitch trick that helped an eSports startup raise $20 million when VCs only wanted AI

    25 May 2026

    Peec, one of Berlin’s up-and-coming startups, more than doubled annual revenue in months to $10 million, sources say

    23 May 2026

    Convective Capital Raises $85M Fund to Build Disaster Resilience

    22 May 2026

    Sam Altman does a ‘mic drop’ pitch to every Y Combinator startup

    21 May 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»The Indian pharmacy chain giant exposed customer data and internal systems
Security

The Indian pharmacy chain giant exposed customer data and internal systems

techtost.comBy techtost.com14 February 202603 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
The Indian Pharmacy Chain Giant Exposed Customer Data And Internal
Share
Facebook Twitter LinkedIn Pinterest Email

A security flaw at one of India’s largest pharmacy chains allowed outsiders to gain full administrative control of its platform, exposing customer order data and sensitive drug control functions, TechCrunch has learned exclusively.

The issue affected DavaIndia Pharmacy, the pharmacy division of Zota Healthcare, which operates a large network of retail stores across India. Security researcher Eaton Zveare told TechCrunch that he discovered the flaw after spotting insecure “super admin” APIs on DavaIndia’s website and sharing private information with Indian cybersecurity authorities.

The bug is now fixed and Zveare revealed his findings.

The report comes as Zota Healthcare is rapidly scaling up the retail business of DavaIndia Pharmacy. The Gujarat-based company has more than 2,300 DavaIndia stores across India, including 276 new points of sale announced in January and plans to add another 1,200 to 1,500 the next two years.

Zveare told TechCrunch that the flaw stemmed from insecure admin interfaces, which allowed unauthenticated users to create “super admin” accounts with elevated privileges.

With that level of access, an attacker could view thousands of online orders containing customer information, modify product listings and prices, create discount coupons and change settings governing whether certain drugs require a prescription, the researcher said.

Based on system timestamps, Zveare said the vulnerable administrative interfaces appeared to be live as of late 2024. The access revealed nearly 17,000 online orders and administrative controls covering 883 stores, he said, allowing for changes to product pricing, prescription requirements and promotional discounts. Zveare said the access allowed modifications to website content that could have been used to distort or disrupt.

Pharmacy order data can be particularly sensitive as it may reveal information about an individual’s health status, medications or other private purchases. Exposure of such data, even without evidence of misuse, carries increased risks to patient privacy and security compared to other consumer information.

“Customer information was linked to their orders,” Zveare said. “This includes name, phone numbers, email IDs, postal addresses, total amount paid and products purchased. As this is a pharmacy, the products purchased could be considered private and even embarrassing to some people.”

Zveare said he reported the issue to CERT-In, India’s national cyber emergency response agency, in August 2025. The vulnerability was patched within weeks, though confirmation from the company took longer and was given to cyber authorities in late November, he said.

Sujit Paul, CEO of Zota Healthcare, did not respond to emails sent by TechCrunch last month. The researcher said there was no indication that the flaw had been exploited before it was patched.

chain customer cyber security data data report DavaIndia Exclusive exposed giant Indian Internal pharmacy systems Zota Healthcare
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleScore, the dating app for people with good credit, is back
Next Article YouTube introduces an AI playlist maker for Premium users
bhanuprakash.cg
techtost.com
  • Website

Related Posts

UK Visa Portal Revealed Thousands of Applicants’ Passports and Selfies — Then Invited Lawyers to Ask Us

27 May 2026

UK Visa portal leaked thousands of applicant passports and selfies online – and hasn’t fixed the leak

27 May 2026

Ghost hackers: the unsolved cybersecurity mystery

26 May 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Meta launches Instagram, Facebook and WhatsApp subscriptions, with more to follow, including AI plans

27 May 2026

UK Visa Portal Revealed Thousands of Applicants’ Passports and Selfies — Then Invited Lawyers to Ask Us

27 May 2026

SOND, a sleep tech startup from former Bose sleep chief, exits stealth with $7 million

27 May 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Disrupt 2026 Early Bird ticket savings expire in 3 days

27 May 2026

Disrupt 2026 Early Bird ticket prices end May 29

26 May 2026

Startup Battlefield 200 applications close before May 27 | TechCrunch

26 May 2026
Startups

SOND, a sleep tech startup from former Bose sleep chief, exits stealth with $7 million

What we’re looking for in Startup Battlefield 2026 and how to apply in time for the May 27 deadline

What ClickUp’s mass layoff tells us about the future of work

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.