The findings, shared exclusively with Decode, expose a severe data protection failure, potentially compromising the personal and medical records of lakhs of patients across Apollo’s network. Beyond the exposed zip file, researchers uncovered far more serious flaws in Apollo’s systems that could have allowed attackers to dig even deeper and access highly sensitive data. The security researchers, Akshay and Viral, had promptly reported the breach to Apollo Hospitals on January 10, just a few hours after discovering the exposed file.