The Supreme Court on Thursday allowed interim bail to a cyber-security researcher accused by the Chennai Police of unauthorisedly accessing computer networks and extracting insurance-related data.A Bench headed by Chief Justice of India Surya Kant issued notice to the State of Tamil Nadu, returnable on September 18.The petitioner-cyber researcher, Himanshu Pathak, had moved the Supreme Court after the Madras High Court, on July 3, rejected his plea to quash the chargesheet filed against him by the CCB Cyber Crime Police Station for offences under Sections 66 (punishment for accessing computer systems or networks without permission) read with 43(b) (extraction of data from a computer) under the Information Technology Act.The special leave petition filed by Mr. Pathak, besides the State of Tamil Nadu, has arraigned Star Health and Allied Insurance Co. Ltd as respondents. Mr. Pathak was represented by advocates Prashant Bhushan and Cheryl Dsouza. Advocate B. Karunakaran accepted notice on behalf of the State. Advocate Shloka Narayanan, who appeared on caveat on behalf of the respondent insurance company, accepted notice on behalf of her client.The court asked the State to also “furnish details of similar cases/criminal antecedents, if any, pending/registered against the petitioner”.The Bench directed the petitioner to appear before the Saidapet Magistrate court concerned to furnish bail bonds to be admitted to interim bail. The apex court also allowed the petitioner to apply for exemption from personal appearance.The petition argued that the case raised “important questions concerning the threshold at which criminal prosecution under Sections 43(b) and 66 may be legitimately be permitted to proceed and the duty of the High Court to interdiction prosecutions, which, even if accepted at their highest, fail to disclose the essential ingredients of the alleged offence”.The petitioner’s case was that he, while accessing the insurance records of his father’s policy issued by the insurance company in 2022, “discovered that its digital infrastructure exposed complete policyholder records through an unsecured legacy API which responded to unauthenticated requests merely upon alteration of the policy number”.The petitioner blamed “pre-existing vulnerability” in the company’s own legacy application. He said he had also communicated with CERT-In (Indian Computer Emergency Response Team).The petition also recorded the prosecution version which said the petitioner “deliberately accessed Respondent 2’s (company) computer resources without authorisation, extracted approximately 8000 policyholder records, demanded annual consultancy charges of USD 65000 together with monthly maintenance charges of USD 3000 and threatened leaking of confidential customer information…” Published - August 07, 2026 12:46 am IST
SC allows interim bail to cyber-security researcher in case relating to unauthorised accessing of computer networks
Supreme Court grants interim bail to cyber-security researcher accused of unauthorized access to computer networks and data extraction.








