Dr Lal Pathlabs Left Millions of Patients’ Sensitive Data on Public Server: Report

Dr Lal Pathlabs was reportedly storing hundreds of spreadsheets in a public bucket hosted on Amazon Web Services (AWS).

Advertisement
By Tasneem Akolawala | Updated: 8 October 2020 18:27 IST
Highlights
  • Dr Lal Pathlabs rectified the error within hours of disclosure
  • Expert says exposed storage bucket had millions of users’ sensitive infor
  • This included data like phone number and address of the patient

Australia-based security expert Sami Toivonen first discovered Dr Lal Pathlabs sensitive data

Dr Lal PathLabs reportedly left sensitive data of millions of users on a public server, allegedly allowing anyone to access this information, in a major security lapse. The lab testing company is one of the largest in India and has received approvals from the Indian government for testing COVID-19 patients as well. The firm was reportedly storing hundreds of spreadsheets in a public storage bucket hosted on Amazon Web Services (AWS), until it was informed of the security lapse by an expert. This storage bucket could be accessed by anyone without the need for a password. The spreadsheets contained sensitive information like patient name, address, phone number, among other things.

TechCrunch reports that Australia-based security expert Sami Toivonen first discovered this sensitive data last month, and he immediately reported this lapse of security to Dr Lal PathLabs. While the company took the necessary measures to shut down access to the storage bucket, it did not respond to Toivonen, according to the report. There is no clarity on how long this data was public, but it gave access to all of the sensitive patient information – to anyone who wanted it.

Toivonen told the publication that the exposed storage bucket had millions of individual patient booking information. The hundreds of spreadsheets that were stored on the AWS public server had information like patient's name, address, gender, date of birth, phone number, and details of the test that the patient is taking. Some of the bookings even had information on test result, for instance, if a patient had tested COVID-19 positive or not.

Advertisement

“I'm glad that they secured it within a few hours after I contacted them because this kind of exposure with millions of patient records could be misused in so many ways by the malicious actors.I was also a little surprised that they didn't respond to my responsible disclosure,” Toivonen told the publication.

Advertisement

Apart from not acknowledging Toivonen, Dr Lal PathLabs has also not offered any public announcement of this data breach. There is also no clarity on whether the organisation has informed the affected patients or not. This little lapse is a prime example of how complacent large organisations still are with storing sensitive information online. Companies, especially the big ones, need to be aware and educated of how to securely store user data on servers.


How to find the best deals during online sales? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Apple Launches iPhone 17 at 'Awe Dropping' Event With These Upgrades
  2. Apple Launches iPhone 17 Pro, 17 Pro Max With These Massive Upgrades
  3. Apple Watch Series 11, Ultra 3, SE Launched With These Health Features
  4. iPhone 17 Launch Highlights: iPhone 17 Series, AirPods 3, and More Launched
  5. Apple MacBook Air M4 Available With Up to Rs. 16,000 Discount via Amazon
  6. AirPods Pro 3 Launched: Featuring Lossless Audio and a Redesigned Case
  7. iQOO 15, iQOO Neo 11 Series Details Tipped; Might Feature 7,000mAh Battery
  8. Tecno Spark Slim Listed Online; Colour Options, Specifications Revealed
  9. Apple Launches iPhone Air as the Slimmest iPhone to Date
  10. Google Breaks Into Top Five Premium Smartphone Brands as Pixel 9 Sales Surge
  1. iPhone 17 Pro, iPhone 17 Pro Max Are Here: Massive Camera Upgrades, and A19 Pro Chip
  2. iPhone Air Launched: Ultra-Slim Form Factor, Apple Intelligence Features, and More
  3. iPhone 17 Launched: A19 Chip, Apple Intelligence, and More
  4. Apple Watch Series 11, Ultra 3, and SE Launched: Thinner Design and New Health Sensors
  5. AirPods Pro 3 Launched: Featuring Lossless Audio and a Redesigned Case
  6. Tecno Spark Slim Full Specifications Revealed; Features MediaTek Helio G200 SoC, 5.93mm Thick Build
  7. Samsung Galaxy S26 Ultra Tipped to Feature Thicker Rear Camera Module Comprising 50-Megapixel Telephoto Camera
  8. Hollow Knight: Silksong Has Reportedly Crossed 5 Million Players in 3 Days
  9. Apple Powerbeats Fit Colour Options, Key Features Leaked; May Offer Up to 30 Hours Total Battery Life
  10. Global Premium Smartphone Sales Hit Record High in H1 2025 as Google Re-Enters Top Five: Counterpoint
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.