Medibank cyber attack criminal claims to have stolen customer data from ahm international student policies 20221020 p5ylnk.html – Breaking News & Latest Updates 2026
Advertisement
Advertisement
This was published 3 years ago

Medibank cyber-attack a 'dog act' as customer medical data held to ransom

Savannah Meacham

Powered by

The Medibank cyber attack has been described as a "dog act" after data from 100 customer policies, including personal information such as Medicare numbers and medical history, was stolen.

Home affairs minister Clare O'Neil slammed the hacker who claims to have stolen 200GB of customer data and is holding Medibank to ransom over the information.

"Financial crime is a terrible thing but ultimately a credit card can be replaced, but the threat being made here to make the private and personal health information of Australians made available to the public is a dog act," she said.

Advertisement

READ MORE: Four states staring down the barrel of another floods crisis

200GB of customer data has allegedly been stolen by a criminal. 

The health insurer earlier revealed a criminal has shown the company a sample of 100 policies containing customers' personal data.

"We believe (the data) has come from our ahm and international student systems," Medibank said in a statement.

"That data includes first names and surnames, addresses, dates of birth, Medicare numbers, policy numbers, phone numbers and some claims data.

"Claims data includes the location of where a customer received medical services, and codes relating to their diagnosis and procedures."

The criminal also claimed to have stolen other information, Medibank said, including data related to credit card security, but that has not yet been verified by internal investigations.

O'Neil confirmed the data shown as a sample is Medibank customer information.

Advertisement

READ MORE: Jury deliberates Bruce Lehrmann verdict

Home affairs minister Clare O'Neil addresses Medibank hack.

Home affairs minister Clare O'Neil has called the Medibank hack a "dog act". 9News

The provider said affected customers will be directly contacted to inform them of the data breach.

"We expect the number of affected customers to grow as the incident continues," Medibank said.

Advertisement
Advertisement

O'Neil warned the initial sample of 100 policies is just a look at how much data may have been stolen in the cyber attack.

"It tells us something about what a broader theft of data may look like in Medibank and it includes a very broad scope of information," she said.

CEO David Koczkar has "unreservedly" apologised to customers for the attack on the health insurer.

Advertisement

"I know that many will be disappointed with Medibank and I acknowledge that disappointment," he said.

"This cybercrime is now the subject of an investigation by the Australian Federal Police.  

"We will learn from this incident and will share our learnings with others."

READ MORE: World's second most deadly land snake curls up in public toilets

Advertisement
Advertisement
Generic image of Medibank, Bourke Street, Docklands.

Government agencies are assisting Medibank to investigate the hack. Photograph by Chris Hopkins

Australian Signals Directorate's Australian Cyber Security Centre and the AFP are investigating the cyberattack and helping to deal with the fallout of the hack.

O'Neil said involving the AFP and other government agencies is to prevent the possession of the data actually harming Australians.

"The smartest people in the Australian government are working directly with Medibank to try to ensure that this horrendous criminal act does not turn into what could be irreparable harm to some Australian citizens," she said.

Advertisement

Medibank has entered a trading halt until further notice.

The incident comes just weeks after the major Optus hack which exposed at least 2.1 million personal identification numbers.

email icon

Contact us

Share a tip-off, video or photo with us

Most viewed in Australia

More to explore