EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/medibank-breach-2022
149/430

File EL-0282CriticalResolvedData Breach / Ransomware Attack

Medibank Private Health Data Breach

Also filed as Medibank Ransomware Attack · Medibank Data Breach

The Medibank Private Health Data Breach was a major ransomware attack that compromised the personal health information of millions of Australians. The attackers, attributed to the REvil group, encrypted critical systems and exfiltrated vast amounts of sensitive data. The incident highlighted significant vulnerabilities in the Australian healthcare data infrastructure.

  • #medibank
  • #revil
  • #ransomware
  • #healthcare-data
  • #australia
  • #pii
  • #cybersecurity
Notoriety8/10
Event
13 Oct 2022
Disclosed
13 Oct 2022
Target
Medibank Private
Actor
REvil
Scale
Multiple Terabytes (TBs)
Status
Resolved

01Summary

The breach was publicly disclosed on October 13, 2022, following a sophisticated ransomware attack targeting Medibank Private. The attackers gained initial access and subsequently deployed ransomware, encrypting core operational systems. Crucially, the threat actors engaged in 'double extortion,' not only encrypting data but also stealing and threatening to publish highly sensitive personal health records. The data compromised included medical records, personal identifiers, and financial details belonging to millions of policyholders. Medibank was forced to pay a ransom, though the exact amount was not publicly disclosed. The incident led to intense scrutiny of Australia's digital health security standards and prompted significant regulatory reviews.

02Background

The Australian healthcare sector relies heavily on digital records, making it a prime target for sophisticated cybercriminals. Prior to this incident, concerns regarding the centralization and security of private health data were already growing. The attack exploited systemic weaknesses in network segmentation and access controls, allowing the threat actors to maintain persistence and escalate privileges over an extended period.

03Key revelations

  1. 01The theft of highly sensitive medical records, including diagnoses and personal identifiers.
  2. 02The confirmation that the attackers were capable of exfiltrating data before encrypting systems (double extortion).
  3. 03The breach exposed systemic weaknesses in the security protocols of major Australian private health insurers.

04Technical analysis

The attack utilized a sophisticated ransomware payload, likely a variant of REvil, which focused on encrypting file shares and critical databases. Initial access was suspected to involve compromised credentials or a vulnerability in a perimeter system. The attackers achieved lateral movement by exploiting internal network trust relationships, allowing them to map the network and locate high-value data repositories. Exfiltration was achieved through large-scale data transfer protocols, confirming the double extortion model.

Attack vector
Compromised credentials or unpatched vulnerability in perimeter systems (suspected)
Attack method
Ransomware deployment and data exfiltration (Double Extortion)
Initial access
Compromised Credentials / Vulnerability Exploitation
Lateral movement
Internal Network Exploitation / Credential Harvesting
Persistence
Backdoors / Scheduled Tasks (Suspected)
Exfiltration
Secure File Transfer Protocol (SFTP) or similar large-scale data transfer
Tool / malware
REvil Ransomware
Malware family
REvil
Malware type
Ransomware

Vulnerabilities exploited

  • Unknown (Likely zero-day or misconfiguration)

MITRE ATT&CK techniques

  • T1078 (Valid Accounts)
  • T1566.001 (Phishing)
  • T1486 (Data Encrypted for Impact)
  • T1041 (Exfiltration Over C2 Channel)

05Threat actor

REvil is a highly sophisticated, financially motivated ransomware group known for its aggressive tactics and high-profile targets. They are responsible for numerous major breaches globally and are known for demanding large ransoms in cryptocurrency, often targeting critical infrastructure and large corporations.

Aliases

  • BlogXX

MITRE groups

  • TA0011

Attribution sources

  • Mandiant
  • CISA
  • Security Industry Reports

06Victims and impact

Additional victims

  • Medibank's associated service providers

Countries affected

  • Australia

07Data exposed

Data types

  • Personal Identifiable Information (PII)
  • Health Records
  • Financial Records
  • Medical History
  • Credentials

Notable documents

  • Patient Medical Records
  • Policyholder Financial Details

08Financial damage

The total financial damage includes regulatory fines, remediation costs, and reputational damage, estimated to be in the hundreds of millions of AUD.

09Timeline

  1. 2022-10-13Breach discovered and publicly disclosed; ransomware payload deployed.
  2. 2022-10-13Medibank confirms a major cyber incident and begins remediation efforts.
  3. 2022-10-20Initial systems remain offline, impacting core services.
  4. 2022-12-01Medibank announces the phased restoration of services and security improvements.

10Key figures

  • Medibank CEOExecutive Leadership · Medibank PrivateAustralianOversaw crisis management and public disclosure.

11On the record

We are working with law enforcement and cybersecurity experts to contain the damage and restore services.

Medibank Spokesperson, Initial public statement following the discovery of the ransomware attack.

12Reaction and fallout

Public reaction

The public reaction was characterized by widespread alarm and anger, particularly concerning the exposure of sensitive medical data. There was significant public outcry demanding stronger government regulation of private health data storage and cyber resilience.

Political impact

The breach triggered immediate political debate regarding the adequacy of Australia's national cyber security framework. It led to calls for mandatory, standardized data protection protocols across the entire private health sector.

13Legal

The incident resulted in multiple class-action lawsuits and intense regulatory scrutiny from the Australian Information Commissioner (OAIC). Medibank faced significant reputational and financial penalties.

Prosecutions

  • REvil GroupUnattributed (Ongoing investigation)
    Charge
    Cybercrime / Data Theft
    Jurisdiction
    International

Civil lawsuits

  • Class-action lawsuits filed by affected policyholders seeking compensation for identity theft risk and distress.

14Aftermath

Policy changes

  • Increased focus on mandatory multi-factor authentication (MFA) for critical infrastructure.
  • Calls for a national data security framework for the healthcare sector.

Regulatory changes

  • Increased scrutiny and potential amendments to the Privacy Act 1988 regarding data breach notification and security standards.

Security improvements

  • Mandatory implementation of advanced endpoint detection and response (EDR) solutions.
  • Improved network segmentation between operational technology (OT) and information technology (IT) systems.

15Significance and legacy

Significance

This breach is a landmark case in Australian cyber history, demonstrating the extreme vulnerability of centralized, highly sensitive private health data. It set a new precedent for the financial and reputational risks associated with ransomware in critical infrastructure, forcing a national conversation on data sovereignty and cyber resilience.

Legacy

The Medibank breach accelerated the adoption of zero-trust architecture principles within Australian healthcare providers. It also increased the global focus on the legal and ethical implications of 'double extortion' ransomware, where data theft is used as a primary leverage point.

16Disclosure and media

Authentication
Forensic Analysis

Media partners

  • The Sydney Morning Herald
  • ABC News

Publishing organisations

  • Australian Government
  • Media Outlets

17Related files

Inspired by

  • medibank-breach-2022

18Field notes

  1. 01The breach was one of the most expensive cyber incidents in Australian history at the time of disclosure.
  2. 02The attackers' ability to exfiltrate data before encryption confirmed the shift toward 'double extortion' tactics globally.

19Resolution

Medibank eventually restored services and implemented significant security upgrades, including enhanced network monitoring and data encryption protocols, though the full extent of the damage remains a subject of ongoing legal and regulatory review.

20Sources

Official documents

  • Australian Information Commissioner (OAIC) Reports
  • Medibank Annual Reports (Post-Breach)

References

  1. [1]ABC News Reporting
  2. [2]Australian Government Cyber Security Agency Advisories
  3. [3]Medibank Official Statements
Fact sheetEL-0282

Dates

Event
13 Oct 2022
Started
13 Oct 2022
Ended
20 Oct 2022
Duration
19 days
Discovered
13 Oct 2022
Disclosed
13 Oct 2022
Resolved
1 Dec 2022
Ongoing
No

Target

Organisation
Medibank Private Limited
Type
Healthcare
Sector
Health Insurance
Country
Australia

Actor

Name
REvil
Type
Ransomware Gang
Motivation
Financial extortion through data encryption and theft (double extortion)
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Multiple Terabytes (TBs)
Sensitivity
Top Secret
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Bitcoin (BTC)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.