Hacker threatens release of Medibank data

November 08, 2022 02:34 PM AEDT | By AAPNEWS
Image source: AAPNEWS

The clock is ticking for Medibank to pay a ransom fee or a ransomware group will release the client data it's stolen from Australia's largest health insurer, the hackers claim.

Medibank has confirmed almost 500,000 health claims were accessed along with personal information when an unnamed group hacked into its system weeks ago.

At about midnight AEDT on Tuesday, a ransomware group posted to its dark web blog that "data will be publish (sic) in 24 hours".

"P.S. I recommend to sell (sic) medibank stocks."

The post did not include data samples to back up the threat.

"This is horrendous but not unsurprising if you look at ransomware like a business," cybersecurity expert Troy Hunt said on Twitter on Tuesday.

"If they *don't* dump the data publicly, what message does that send to future customers?"

Medibank, which this week said paying a ransom would encourage further crime, apologised again on Tuesday.

It advised customers to be alert for any phishing scams via phone, post or email.

"We knew the publication of data online by the criminal could be a possibility but the criminal's threat is still a distressing development for our customers," chief executive David Koczkar said on Tuesday

Home Affairs Minister Clare O'Neil said Medibank's decision not to pay a ransom to cyber criminals was in line with government advice.

Medibank is certainly not alone in refusing to pay a ransom demand, with a recent report finding 19 per cent of Australian companies responded to ransomware attacks by paying the fee.

Mimecast's 2022 State of Ransomware Readiness report found 20 per cent of companies were asked to pay between $500,000 and $999,999 for their information

Some 13 per cent of the businesses surveyed said the total cost of the ransomware attacks they'd experienced was between $1 million and $2 million.

Appearing at a Senate estimates hearing on Tuesday, Australian Federal Police commissioner Reece Kershaw fired a warning at businesses to ensure they contacted authorities as early as possible when a data breach might be occurring.

With the FBI now helping the AFP track down those behind the Medibank and Optus data breaches, Mr Kershaw said the long and complex investigations would use significant resources.

"It's like any crime scene," he said.

"The longer it takes relevant agencies to be informed, the harder it is for perpetrators to be identified, disrupted or brought to justice."

Meanwhile, two law firms, including one behind a successful case involving an NSW Ambulance data breach, say they believe Medibank betrayed customers and breached the Privacy Act by not stopping the hack.

The insurer faces a possible class action over the hacking of the 9.7 million current and former customers.

"This latest data breach exposes the lack of safeguards in place to prevent such personal and private information being released to wrongdoers and Medibank and Ahm have failed policyholders in these circumstances," Bannister Law and Centennial Law said in a statement late on Monday.

No case has been filed with a court.

The hacker accessed the health claims of about 160,000 Medibank customers, about 300,000 claims from customers of offshoot Ahm and about 20,000 international customers.

Names, dates of birth, addresses, phone numbers and email addresses were also accessed, raising concerns about future identity fraud.

No credit card or banking details were accessed.


Disclaimer

The content, including but not limited to any articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, graphs, charts, animations and video (Content) is a service of Kalkine Media Pty Ltd (“Kalkine Media, we or us”), ACN 629 651 672 and is available for personal and non-commercial use only. The principal purpose of the Content is to educate and inform. The Content does not contain or imply any recommendation or opinion intended to influence your financial decisions and must not be relied upon by you as such. Some of the Content on this website may be sponsored/non-sponsored, as applicable, but is NOT a solicitation or recommendation to buy, sell or hold the stocks of the company(s) or engage in any investment activity under discussion. Kalkine Media is neither licensed nor qualified to provide investment advice through this platform. Users should make their own enquiries about any investments and Kalkine Media strongly suggests the users to seek advice from a financial adviser, stockbroker or other professional (including taxation and legal advice), as necessary.
The content published on Kalkine Media also includes feeds sourced from third-party providers. Kalkine does not assert any ownership rights over the content provided by these third-party sources. The inclusion of such feeds on the Website is for informational purposes only. Kalkine does not guarantee the accuracy, completeness, or reliability of the content obtained from third-party feeds. Furthermore, Kalkine Media shall not be held liable for any errors, omissions, or inaccuracies in the content obtained from third-party feeds, nor for any damages or losses arising from the use of such content.
Kalkine Media hereby disclaims any and all the liabilities to any user for any direct, indirect, implied, punitive, special, incidental or other consequential damages arising from any use of the Content on this website, which is provided without warranties. The views expressed in the Content by the guests, if any, are their own and do not necessarily represent the views or opinions of Kalkine Media. Some of the images/music that may be used on this website are copyrighted to their respective owner(s). Kalkine Media does not claim ownership of any of the pictures displayed/music used on this website unless stated otherwise. The images/music that may be used on this website are taken from various sources on the internet, including paid subscriptions or are believed to be in public domain. We have made reasonable efforts to accredit the source wherever it was indicated as or found to be necessary.
This disclaimer is subject to change without notice. Users are advised to review this disclaimer periodically for any updates or modifications.


AU_advertise

Advertise your brand on Kalkine Media

Sponsored Articles


Investing Ideas

Previous Next
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.