Breach report
HealthcareMedibank
Ransomware gang threatens to publish thousands of Australians' health data
Russian-linked extortionists stole data on 9.7 million Medibank customers and, after Australia's largest health insurer refused to pay, dumped sensitive claims records on the dark web, prompting the country's first cyber sanctions.
Reported by TechCrunch
Records exposed
9.7M
9.7 million current and former customers
Scale vs. largest on file
- When
- 2022
- How they got in
- Stolen third-party contractor credentials followed by data theft and extortion
- Sector
- Healthcare
In October 2022, Medibank, Australia's largest private health insurer, detected unusual activity on its network. Within days it confirmed that a criminal had stolen data and was demanding payment. The company eventually said personal information on about 9.7 million current and former customers had been taken, including its budget brand ahu and some international student policyholders, roughly a third of Australia's population.
Investigators later found that the attacker had used login credentials belonging to a third-party IT contractor, which had been stolen by information-stealing malware, to access Medibank's systems. Once inside, the intruder extracted about 520 gigabytes of data over several weeks. Around 480,000 people had health claims data taken, including codes that could reveal diagnoses and procedures.
Medibank refused to pay a ransom demand reported at about US$10 million, citing government and expert advice that payment was unlikely to guarantee deletion. The group, which Australian police linked to Russia-based criminals associated with the REvil ransomware ecosystem, responded by publishing batches of records on a leak site in November 2022, including files it labeled as relating to mental health, drug and alcohol treatment and pregnancy terminations.
The response was unprecedented for Australia. The Australian Federal Police publicly attributed the attack to Russian actors, and in January 2024 the government imposed its first cyber sanctions on a Russian national, Aleksandr Ermakov, over his alleged role. The Office of the Australian Information Commissioner sued Medibank in federal court in 2024, alleging it had failed to take reasonable steps to protect personal information, and shareholders and customers brought class actions. The attack came weeks after the Optus telecom breach and helped drive legislation that sharply raised maximum privacy penalties.
The Medibank case illustrated how health data can be weaponized for extortion even when no systems are encrypted, and how a single contractor's compromised password can open the door to an entire customer base. It also showed the personal cost of refusing to pay: while officials backed the decision, customers bore the risk of having their most sensitive information exposed. Medibank's share price fell sharply as the scale of the theft emerged, and the insurer later reported tens of millions of Australian dollars in response costs.