Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Davaindia Generic Pharmacy

Davaindia Generic Pharmacy Vendor Cyber Rating & Cyber Score

davaindia.com

Davaindia Generic Pharmacy a brand of Zota Healthcare Ltd. revolutionized the Indian Healthcare scenario by providing high quality generic medicines at a very low cost. Davaindia’ Generic Pharmacy offer a comparative cost benefit of upto 90% on its generic medicines which is a significant savings on medicine cost and hence since its launch at the end of 2017, Davaindia generic pharmacy has instituted more than 550+ plus retail franchise and with 4.7 lakh happy customers across the length and breadth of India and the number is growing day by day. Davaindia Generic pharmacy is India’s largest private generic pharmacy retail chain that offers a range of more than 2000 products which cover high quality generic medicines to treat acute and


DGP A.I CyberSecurity Scoring

DGP
Company Information
Website:http://www.davaindia.com/
Employees number:1,182
Number of followers:9,931
NAICS:71394
Industry Type:Wellness and Fitness Services
Homepage:davaindia.com
DGP Risk Score (AI oriented)
Between 700 and 749
logo
DGPWellness and Fitness Services
Updated:
04/04/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
DGP Global Score (TPRM)
xxxx
logo
DGPWellness and Fitness Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

DGP
DGPModerate
Current Score
749Ba (MODERATE)
01000
2 incidents
-11 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
749Before Incident
FEBRUARY 2026
755Before Incident
Vulnerability
13 Feb 2026DGP
Zota Healthcare and DavaIndia Pharmacy: Indian pharmacy chain giant exposed customer data and internal systems

DavaIndia Pharmacy Security Flaw Exposed Customer Data and Admin Controls

749After Incident
CRITICAL-6
DAV1771050672
DavaIndia Pharmacy Security Flaw Exposed Customer Data and Admin Controls A critical security vulnerability in DavaIndia Pharmacy, the pharmacy arm of India’s Zota Healthcare, allowed unauthorized access to full administrative controls and sensitive customer order data. The flaw, discovered by security researcher Eaton Zveare, stemmed from insecure "super admin" application programming interfaces (APIs) on the company’s platform. The exposure enabled unauthenticated users to create high-privilege accounts, granting access to nearly 17,000 online orders and administrative functions across 883 stores. Attackers could have viewed customer details including names, phone numbers, email addresses, and purchased medications while also modifying product prices, prescription requirements, and promotional discounts. The vulnerable interfaces had been active since late 2024, with system timestamps confirming the exposure. Zveare reported the issue to India’s national cyber emergency response agency, CERT-In, in August 2025. The flaw was patched within weeks, though official confirmation from Zota Healthcare was delayed until late November. The company, which operates over 2,300 retail outlets across India and plans to expand further, did not respond to requests for comment. There is no evidence the vulnerability was exploited before being fixed. The incident highlights the heightened privacy risks associated with pharmacy data, as exposed order details could reveal sensitive health information. Zota Healthcare’s rapid expansion including 276 new stores announced in January 2025 and plans for 1,200–1,500 additional outlets underscores the potential scale of such vulnerabilities.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Data Compromised: Customer order data (names, phone numbers, email addresses, purchased medications), administrative controls (product prices, prescription requirements, promotional discounts)Systems Affected: DavaIndia Pharmacy platform, 883 storesOperational Impact: Potential unauthorized modification of product prices, prescription requirements, and promotional discountsBrand Reputation Impact: Potential brand reputation damage due to exposure of sensitive health informationIdentity Theft Risk: High (exposure of personally identifiable information and health data)
DATA BREACH
Type Of Data Compromised: Customer order data, administrative controlsNumber Of Records Exposed: Nearly 17,000 online ordersSensitivity Of Data: High (personally identifiable information, health/medication data)Personally Identifiable Information: Names, phone numbers, email addresses, purchased medications
JANUARY 2026
755Before Incident
DECEMBER 2025
755Before Incident
NOVEMBER 2025
754Before Incident
OCTOBER 2025
754Before Incident
SEPTEMBER 2025
754Before Incident
AUGUST 2025
770Before Incident
Vulnerability
01 Aug 2025DGP
Zota Healthcare and DavaIndia Pharmacy: Indian pharmacy chain giant exposed customer data and internal systems

DavaIndia Pharmacy Flaw Exposed Sensitive Customer Data, Allowed Unauthorized 'Super Admin' Access

754After Incident
CRITICAL-16
ZOTDAV1771331028
DavaIndia Pharmacy Flaw Exposed Sensitive Customer Data, Allowed Unauthorized "Super Admin" Access A critical security vulnerability in DavaIndia Pharmacy, the pharmacy arm of Zota Healthcare with over 2,300 stores across India, allowed unauthenticated users to create "super admin" accounts with full system privileges. The flaw, introduced in late 2024, exposed highly sensitive customer data tied to nearly 17,000 online orders across 800+ stores, including health conditions, medications, personal details, and purchase histories. Security researcher Eaton Zveare discovered the bug, which enabled attackers to: - Access and exfiltrate customer data (names, phone numbers, emails, addresses, and purchased products). - Tamper with product listings, including modifying prices and prescription requirements. - Create unauthorized discounts, coupons, and alter administrative controls. Zveare described the exposed data as potentially "private and even embarrassing" due to the nature of pharmacy purchases. While no evidence suggests malicious exploitation, the flaw remained unpatched until mid-September 2025, following Zveare’s responsible disclosure to CERT-In (India’s national cybersecurity agency) in August 2025. DavaIndia confirmed the fix in late November 2025, though no customer action such as password resets was required, as payment data and other secrets remained secure. The incident highlights risks in handling sensitive health-related data, particularly in large-scale digital pharmacy platforms.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Names, phone numbers, emails, addresses, purchased products, health conditions, medications, purchase historiesSystems Affected: DavaIndia Pharmacy online platformOperational Impact: Unauthorized administrative access, tampering with product listings and discountsBrand Reputation Impact: Potential reputational damage due to exposure of sensitive health dataIdentity Theft Risk: HighPayment Information Risk: None (payment data remained secure)
DATA BREACH
Type Of Data Compromised: Personal identifiable information, health-related data, purchase historiesNumber Of Records Exposed: 17,000 online ordersSensitivity Of Data: High (health conditions, medications)Data Exfiltration: Possible (no evidence of malicious exploitation)Personally Identifiable Information: Names, phone numbers, emails, addresses
JULY 2025
770Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for DGP ?
?
What was DGP's A.I Rankiteo Cyber Score in May 2026 ?
?
What was DGP's A.I Rankiteo Cyber Score in April 2026 ?
?
What was DGP's A.I Rankiteo Cyber Score in March 2026 ?
?
What was DGP's A.I Rankiteo Cyber Score in February 2026 ?
?
What was DGP's A.I Rankiteo Cyber Score in January 2026 ?
?
What was DGP's A.I Rankiteo Cyber Score in December 2025 ?
?
What was DGP's A.I Rankiteo Cyber Score in November 2025 ?
?
What was DGP's A.I Rankiteo Cyber Score in October 2025 ?
?
What was DGP's A.I Rankiteo Cyber Score in September 2025 ?
?
What was DGP's A.I Rankiteo Cyber Score in August 2025 ?
?
What was DGP's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on DGP's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with DGP ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view DGP's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Davaindia Generic Pharmacy Cyber Scoring History | Rankiteo