Breach tracker

Breach report

DavaIndia admin APIs exposed about 17,000 orders and control of 883 stores

ConfirmedDisclosed IndiaHealthcareBy Vivek Kumar
Records UnknownCause Vulnerability
Conceptual illustration: Generic pharmacy parcels, anonymous online-order cards and a digital administrator key under a security lens. Headline: DAVAINDIA DATA EXPOSURE.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

A researcher found open 'super admin' APIs at Zota Healthcare's pharmacy chain that exposed customer orders and store controls. The flaw was fixed after a CERT-In report.

What happened

DavaIndia Pharmacy, the retail arm of Gujarat-based Zota Healthcare with more than 2,300 outlets, had "super admin" APIs (application programming interfaces) on its website that did not check who was calling them, TechCrunch reported on 13 February 2026. A security researcher found that anyone could create a high-privilege account. Timestamps suggested the interfaces had been live since late 2024.

Confirmed vs. claimed

Confirmed by the researcher's findings, reported by TechCrunch: about 17,000 online orders were visible, with customers' names, phone numbers, email addresses, delivery addresses, amounts paid and products bought. Admin access also covered 883 stores. The420.in reported that it allowed changes to prices, discount coupons and prescription requirements for medicines.

Fix: the researcher reported the flaw to CERT-In in August 2025. It was patched within weeks, with formal confirmation in late November 2025.

Unknown: whether anyone else used the access. No malicious use has been reported. Zota Healthcare did not respond to TechCrunch.

Who is affected

People who placed online orders with DavaIndia up to the fix. Medicine purchases can reveal health conditions, which makes this data more sensitive than a typical order list.

What to do

  • Be wary of calls or messages that mention a medicine you bought and offer refunds, "prescription verification" or cheap supplies.
  • Do not pay by link or share OTPs; order only through the official app or site.
  • If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.
  • More steps: what to do after a data breach notice.

Sources

More breaches in India