Supreme Court Issues Notice On Vitraya Technologies' Plea Seeking CBI Probe Into Alleged Medical Data Breach Affecting 2 Lakh Indians
The Supreme Court issued notice on Vitraya Technologies' plea seeking a CBI probe into an alleged cyber attack that reportedly compromised the sensitive medical and personal data of nearly two lakh Indians, while also noting the need to revisit the Information Technology Act
The Supreme Court issued notice on Vitraya Technologies' plea seeking a CBI probe into an alleged cyber attack and medical data breach affecting nearly two lakh Indians
The Supreme Court on Thursday issued notice on a writ petition filed by Vitraya Technologies Pvt. Ltd. seeking a CBI investigation into an alleged large-scale cyber attack and data breach by companies promoted by Bessemer Venture Partners, including Remedinet Technologies Pvt. Ltd., IHX Pvt. Ltd., Medi Assist and Perfios Software Solutions Pvt. Ltd. that purportedly compromised the sensitive personal and medical data of nearly two lakh Indians across six States.
The Bench of Chief Justice of India Surya Kant, Justice Joymalya Bagchi and Justice V. Mohana heard the matter and also permitted dasti service of notice upon the Union of India and the concerned States at the petitioner's request.
The petition alleges that companies promoted by Bessemer Venture Partners, including Remedinet Technologies Pvt. Ltd., IHX Pvt. Ltd., Medi Assist and Perfios Software Solutions Pvt. Ltd., were involved in a coordinated cyber intrusion targeting Vitraya Technologies' digital infrastructure.
Appearing for the petitioner, Senior Advocate K. Parameshwar submitted that the breach resulted in the compromise of highly sensitive personal information, including Aadhaar details, PAN cards, medical records, insurance claim information and other personally identifiable data of approximately two lakh Indian citizens.
He told the Court that the compromised data had allegedly been transferred to a server located in Singapore.
"I filed my complaint in March 2025. It took authorities till August 2025 just to register an FIR. I even gave details of the Singapore server where the data had gone. Yet, the FIR is still against unknown persons. How do I trust this investigation? That is why I am before Your Lordships seeking a CBI inquiry," Parameshwar submitted.
He told the Court that it was only after repeated representations and continuous follow-ups that the Punjab State Cyber Crime Police Station registered FIR No. 16 of 2025 on August 29, 2025. Even then, he argued, the FIR was lodged mechanically under only Sections 66 and 66B of the Information Technology Act against "unknown persons," despite the investigating agency having been supplied with details of the alleged Singapore server and the entities allegedly responsible.
According to the petition, the delay in registration of the FIR, coupled with the failure to conduct any meaningful forensic investigation or seize digital evidence, has raised serious doubts over the fairness and effectiveness of the probe.
During the hearing, Senior Advocate Parameshwar further submitted, "This is a serious case. I have identified where the breaches originated, who is responsible, and where the data has gone."
Taking note of the submissions, the Bench directed issuance of notice.
Justice Bagchi observed that the Court had already requested the Solicitor General to examine the need for amendments to the Information Technology Act. "Mr. Parameshwar, we have already asked the Solicitor General to relook at the Information Technology Act and consider amendments," Justice Bagchi remarked.
Responding to the observation, Parameshwar submitted that the present FIR invoked only Section 66 of the Information Technology Act. "Even today, the FIR invokes only Section 66 of the IT Act. That is not effective at all," he argued.
Senior Advocate K. Parameshwar appeared along with Advocate Nupur Sharma and Advocate Manan Popli for the petitioner company.
About the petition
The writ petition filed through Advocate-on-Record (AoR) Abhinav Agarwal contends that the alleged cyber attack involved sophisticated hacking methods, including brute-force login attempts, mass downloading of confidential records and unauthorised access to Vitraya Technologies' digital systems. It further alleges that the matter involves multi-jurisdictional cybercrime, cross-border transfer of data and nationwide implications for citizens' informational privacy.
Invoking the Supreme Court's judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India, the petitioner has argued that the breach strikes at the heart of the fundamental right to privacy under Article 21 of the Constitution.
Besides seeking transfer of the investigation to the Central Bureau of Investigation, the petition alternatively prays for the constitution of a Court-monitored Special Investigation Team comprising the CBI, CERT-In and other specialised cyber security agencies to conduct an independent, expert-driven and time-bound investigation into the alleged breach.
Relief Sought
In its petition, Vitraya Technologies has sought transfer of the investigation from the Punjab Police to the Central Bureau of Investigation (CBI), alleging that the local probe has been ineffective and lacking in impartiality. Alternatively, it has urged the Supreme Court to constitute a court-monitored Special Investigation Team (SIT) comprising the CBI, CERT-In and other specialised cyber and national security agencies to conduct an independent, expert-driven and time-bound investigation.
The petitioner has also sought directions for the immediate preservation and forensic examination of all electronic evidence connected with the alleged cyber attack, including servers, IP logs, authentication records, cloud infrastructure, digital devices and other relevant data, contending that such measures are essential to prevent the destruction, tampering or disappearance of crucial digital evidence.
Case Title: Vitraya Technologies Pvt. Ltd. v. Union of India
Bench: CJI Surya Kant, Justices Joymalya Bagchi and V. Mohana
Hearing Date: August 6, 2026