© 2023 CyberNews - Latest tech news,
product reviews, and analyses.

If you purchase via links on our site, we may receive affiliate commissions.

Medibank confirms hacker data dump


Australia's biggest health insurer has admitted hackers released more of its stolen medical records, amid media reports that data on millions of its customers is now public.

The Office of the Australian Information Commission (OAIC), the country's privacy regulator, has also begun investigating how the company handles personal information, Medibank said in a statement.

The latest release on the dark web follows progressive uploads, including records of customers' mental health and alcohol use, that began after Medibank said on November 7 it would not pay a ransom. "The raw data we have analysed today so far is incomplete and hard to understand," chief executive David Koczkar said.

"While there are media reports of this being a signal of 'case closed', our work is not over."

On Thursday, the media reported that a blog, believed by cyber experts to be used by the hackers, carried a new post: "Happy Cyber Security Day!!! Added folder full. Case closed." It also included a file that had several compressed files amounting to more than 5GB.

Reuters has not verified the contents of the latest files uploaded on the dark web, a part of the internet accessible only with special software. Medibank did not immediately respond to a question asking whether it believed all stolen data had now been released. Australian Federal Police last month said Russia-based hackers were behind the Medibank cyberattack, which compromised the details of almost 10 million current and former customers.

Medicare revealed the breach on October 13. In an update on December 1, Medibank said there were currently no signs that banking data had been stolen. Personal details accessed by hackers were not enough to enable financial fraud, it added. Six zipped files placed in a folder called "full" and containing raw data believed to have been stolen had been uploaded, Medibank said in a statement.

Australia has been grappling with a recent rise in cyberattacks. At least eight companies, including telecoms company Optus, owned by Singapore Telecommunications, have reported breaches since September.

The OAIC, which is also investigating Optus over the breach, did not immediately respond to a Reuters request for comment on the Medibank investigation. Technology experts have said Australia has become a target for hackers just as a skills shortage leaves an understaffed, overworked cybersecurity workforce ill-equipped to stop attacks.


More from Cybernews:

South Staffs Water admits hackers accessed customer data

Women in digital darkness: 18% more women lack internet access than men

San Francisco police allowed to use lethal force by robots

Spanish police detain scam gang suspects

Espionage leverages infected USB

Subscribe to our newsletter



Leave a Reply

Your email address will not be published. Required fields are marked