INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Medibank Data Breach Exposes Sensitive Customer Information

| 2024-11-20 06:29 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On October 13, 2022, Medibank announced a potential cyberattack after detecting suspicious activity on its network. The Australian company had taken immediate steps to contain the incident and engaged specialized cybersecurity firms. As of that date, there was no evidence that any sensitive data, including customer data, had been accessed. Around 2.8 million customers received an email announcing the incident, stating that no customer data compromise had been detected. However, on October 17, Medibank confirmed that its investigation efforts still hadn't found evidence of customer data being compromised. The company's systems were not encrypted by ransomware during this incident and additional security measures have since been put in place across their network to mitigate the risk.
Technical Mitigations AI-generated
• Isolate and remove access to customer-facing systems, such as ahm and international student policy management systems. • Implement additional security measures across the network, including those recommended by external cybersecurity experts. • Use a technique to detect ransomware threats, such as monitoring for suspicious activity in IT networks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

cy•••••.au
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
REvilREvil
Target & Sectors
FIVE_EYES FIVE_EYES healthhealth
Incident Timeline
‎October 2022
Threat actors published a segment of the stolen Medibank customer database on the dark web, followed by contact with Medibank to provide proof of data compromise.
data_breach 100 stolen customer records
data_breach 20 MB
data_breach 200 identifiable records
data_breach 224 MB
data_breach 414 files
‎2024/11/20
Threat actors accessed and obtained sensitive personal data, including health claims information, of approximately 9.7 million Medibank customers through a ransomware attack that was intercepted before the hackers could encrypt their files.
data_breach 1,000 further ahm policy records
infrastructure 9.7
victims 9.7 Customers
victims 5.1 Medibank customers
victims 2.8 ahm customers
data_breach 1.8 customers Medicare numbers
victims 160,000 Medibank customers
victims 20,000 international customers
Tactical Metrics
Metrics
data_breach
1,000
Further Ahm Policy Records
Metrics
infrastructure
​9.7
Software Version
Metrics
victims
9,700,000
Customers
Metrics
data_breach
100
Stolen Customer Records
Metrics
data_breach
20
Mb
Metrics
victims
5,100,000
Medibank Customers
Metrics
victims
2,800,000
Ahm Customers
Metrics
data_breach
1,800,000
Customers Medicare Numbers
Metrics
victims
160,000
Medibank Customers
Metrics
victims
20,000
International Customers
Metrics
data_breach
200
Identifiable Records
Metrics
data_breach
224
Mb
Metrics
data_breach
414
Files
Intelligence Sources