Vulnerability-Disclosure Complaints Are Not a Writ Substitute When the Complainant Has No Personal Data Breach and the “Vulnerability Test” Is Prima Facie Unauthorised Access

Case: Himanshu Pathak v. Ministry of Electronics and Information
Citation: 2026 MHC 1396 (Madras High Court)
Date: 08.04.2026
Coram: Sushrut Arvind Dharmadhikari, CJ & G. Arul Murugan, J.

1) Introduction

These intra-court appeals (under Clause 15 of the Letters Patent) arose from the dismissal of a batch of writ petitions seeking directions to multiple Union Ministries and regulators (including CERT-In/MeitY, IRDAI and SEBI) to take action against Star Health and Allied Insurance Company Limited (respondent no.7) for alleged vulnerabilities in its customer web portal.

The appellant (a cyber-security service provider and also a policyholder) claimed he discovered website vulnerabilities that could allow access to other policyholders’ information, and complained to authorities when (according to him) action was not taken. The insurer’s case, however, was that the appellant had engaged in unauthorised access/data breach and attempted to monetise the incident by pitching paid “Attack Surface Analysis” and ongoing security assessment services.

Key issues before the Division Bench were: (i) whether writ directions compelling statutory/regulatory action were maintainable in the circumstances; (ii) whether pending civil and criminal proceedings between the parties (concerning the same alleged access/data) justified the writ court’s refusal; and (iii) whether the cyber-incident reporting framework (Section 70B, CERT-In Rules and directions) mandated further action on the appellant’s complaint.

2) Summary of the Judgment

The Division Bench dismissed all writ appeals and affirmed the common order of the writ court. In essence, it held that:

  • The appellant did not plead or show any actual breach/misuse of his own personal data; his case was built on an asserted “possibility” of third-party access.
  • The appellant’s method of “testing” by accessing other policyholders’ data without authorisation was, on the record (including prior judicial findings), prima facie illegal and already the subject of pending civil and criminal proceedings.
  • Authorities had already been intimated by the insurer; CERT-In had responded (as per appellant’s own pleadings) that the issue had been resolved—there was no challenge to that response.
  • The timing, framing and reliefs sought indicated lack of bona fides; the writ petitions were viewed as an attempt to leverage regulatory machinery after the appellant faced injunction and prosecution.
  • Liberty to pursue remedies after the outcome of the pending proceedings was appropriate; no interference was warranted.

3) Analysis

3.1 Precedents Cited (as relied upon in the Judgment)

The judgment did not cite external Supreme Court/High Court precedents. Instead, it relied heavily on earlier orders and proceedings involving the same parties, treating them as determinative context for maintainability and bona fides:

(a) C.S.No.1 of 2023 (order dated 03.01.2023; applications allowed on 07.06.2023)

In the civil suit filed by the insurer, the single judge granted and then made absolute an injunction restraining the appellant from publishing/sharing/dealing with allegedly illegally accessed information. The quoted extract records a prima facie view that the appellant “had accessed the computer system” and “seems to have downloaded the datas”, attracting Section 43 (civil penalty) and Section 66 (criminal offence) of the Information Technology Act, 2000.

Influence on the writ appeals: The Division Bench treated this prima facie finding and the operative injunction as a serious legal impediment to entertaining writ directions premised on the appellant’s asserted “vulnerability discovery”, because the asserted discovery itself arose from conduct already found prima facie unlawful and sub judice.

(b) O.S.A.(CAD)Nos.109 and 110 of 2023 (order dated 12.06.2024)

The Division Bench in the original side appeals continued the interim injunction “till disposal of the main suit” while staying only the direction appointing an Advocate Commissioner.

Influence on the writ appeals: This continuing injunction reinforced the conclusion that the appellant’s claims were intertwined with pending adjudication and that parallel writ-driven regulatory coercion would cut across the pending civil determination.

(c) Crime No.2 of 2023; C.C.No.564 of 2026; and Crl.O.P.No.10781 of 2023 (dismissed on 30.03.2026)

The appellant faced prosecution for offences under Sections 66 and 43(b) of the IT Act; a charge sheet was filed and cognizance taken. His petition to quash the FIR in Crl.O.P.No.10781 of 2023 was dismissed shortly before the present appellate judgment.

Influence on the writ appeals: The pendency of criminal proceedings based on the same factual nucleus supported the court’s view that the appellant’s writ petitions were not a neutral public cause but part of a contested factual matrix, already under criminal adjudication.

3.2 Legal Reasoning

  1. Locus and injury-based framing: The court stressed that the appellant did not assert an actual breach of his own data or resulting misuse. Absent pleaded personal injury, the petitions were viewed as lacking a direct enforceable personal right—especially when filed as ordinary writ petitions rather than a procedurally compliant public interest litigation.
  2. Un-authorised access vs. “ethical testing”: The judgment draws a sharp line between lawful security assessment and unauthorised intrusion. Where a policyholder uses valid credentials but then “tests” methods to access other customers’ restricted data without permission, the court treated the act as prima facie unauthorised access—squarely engaging Section 43/66 issues (already the subject of the suit and prosecution).
  3. Sub judice and parallel-track restraint: While not articulated as a rigid bar on all statutory action whenever a civil suit is pending, the court’s operative rationale was practical and equitable: the appellant’s entitlement to seek consequential action depended on the outcome of proceedings where his conduct and the factual allegations were being tried. Entertaining writ relief would effectively allow him to litigate around the injunction and the criminal case.
  4. Regulatory response already on record: The appellant’s own pleadings acknowledged CERT-In replied that the insurer had intimated the matter and that the “issue had been resolved”. With no challenge to that response, the claim of inaction was held misplaced. Additionally, materials showed the insurer had reported the incident to IRDAI (21.12.2022) and engaged with regulators.
  5. Bona fides and timing: The court treated chronology as significant: the appellant complained to authorities after (i) pitching paid services, (ii) receiving an injunction, and (iii) registration of an FIR. The “verbatim” batch filings and the prayer to disrupt the insurer’s online activity further supported an inference that writ remedies were being used strategically rather than to vindicate a genuine public wrong.

3.3 Impact

  • On cyber-vulnerability disclosure in India: The decision signals judicial skepticism toward “vulnerability discovery” claims where the discoverer obtained access through unauthorised testing, particularly if coupled with commercial solicitation. It implicitly encourages researchers to use authorised channels (bug bounty, written permission, coordinated disclosure) rather than self-directed probing of production systems.
  • On writ strategy against regulated entities: The ruling reinforces that writ courts may decline to compel regulatory action when (i) the complainant shows no personal injury, (ii) the complaint is entangled with disputed facts, and (iii) civil/criminal proceedings already cover the same allegations.
  • On regulators and CERT-In process: While Section 70B and CERT-In Rules provide a reporting-and-direction framework, this judgment indicates that courts will look for concrete regulatory inaction (or a challenge to the regulator’s response) rather than entertain broad directions based on speculative harm.
  • On insurers/financial sector entities: The judgment may be cited to defend against writ-driven disruption of digital services where the entity demonstrates reporting/compliance and remediation, and where the complainant’s conduct is itself under legal challenge.

4) Complex Concepts Simplified

Intra-court appeal (Clause 15, Letters Patent)
An appeal within the same High Court, typically from a single judge to a Division Bench.
Writ jurisdiction
The High Court’s constitutional power (often under Article 226) to issue directions/orders to public authorities; generally not used to resolve heavily disputed facts or private disputes dressed as public causes.
Sub judice
The matter is under active consideration before a court; parallel proceedings may be discouraged if they risk inconsistent findings or circumvent existing orders.
Ad-interim / interim injunction
A temporary court order restraining conduct until the suit is decided (or until further orders). Here, it restrained the appellant from disseminating allegedly illegally accessed data.
Section 43 and Section 66, Information Technology Act, 2000
Section 43 creates civil liability/penalty for unauthorised access, copying, extraction, etc. Section 66 criminalises certain acts under Section 43 when done dishonestly or fraudulently.
CERT-In and Section 70B
CERT-In is India’s national agency for cyber-incident response coordination. Rules and directions prescribe reporting and response mechanisms for certain cyber incidents.
“Vulnerability” vs “unauthorised access”
Finding a flaw is not, by itself, illegal; but probing a live system and accessing restricted third-party data without permission can constitute unauthorised access even if the stated motive is “testing”.

5) Conclusion

The Madras High Court’s core contribution in this decision is a maintainability-and-bona-fides filter for cyber-vulnerability based writ petitions: where the petitioner shows no personal data breach, where the “testing” involves prima facie unauthorised access to others’ data, and where civil/criminal proceedings already govern the factual controversy (including operative injunctions), writ courts will be slow to compel regulators to proceed on the petitioner’s narrative—particularly when the record shows reporting/remediation and a regulator response (CERT-In) already exists.