Industry
HealthTech & Quick Commerce
Date & Timeline
August 2026
Coordinated Disclosure / CERT-In Escalated (August 2026)
Evidence Level
Responsible disclosure
Unauthenticated API Architectural Defeat & Mass PII Exfiltration Mitigation
Challenge
A fast-growing HealthTech quick-commerce delivery platform required a comprehensive security assessment of their micro-fulfillment dark-store API backend prior to expanding across tier-1 metro hubs.
Our Approach
Executed white-box API architecture analysis and black-box dynamic endpoint fuzzing across their mobile API gateways and microservice endpoints.
Impact Found
Identified an unauthenticated API vulnerability across 195+ endpoints exposing 580,000+ customer records, live cart GPS telemetry with sub-meter accuracy, historical prescription data, and real-time operational delivery analytics.
Outcome
Following unacknowledged direct vendor outreach, SDX Shadow Labs escalated the incident to CERT-In (Indian Computer Emergency Response Team). Upon official CERT-In notification, the vendor leadership deployed application-wide authentication middleware and API gateway controls within 24 hours.