Data Breaches

Medibank suffers breach impacting 3.9 million customers

0

Australian health insurance firm Medibank revealed that the personal information of all of its customers had been accessed during a recent ransomware attack.

The firm stated in an update that the attackers had access to “significant amounts of health claims data” as well as personal data belonging to its ahm health insurance subsidiary and international students.

Medibank, one of the largest Australian private health insurance providers, serves around 3.9 million customers across the country.

The company added that they have evidence that the hacker has removed some of this data and it is now likely that they have stolen further personal and health claims data. They expect the number of affected customers might grow substantially.

The investigation process is ongoing and the firm is continuing its probe to determine what specific data has been stolen in the attack. They will directly notify affected customers of the matter.

Last week, Medibank assured its customers that there was no evidence of any customer data having been accessed and claimed the hackers didn’t encrypt anything before they were stopped.

A few days later, the ransomware gang made contact to extort the company, providing a sample of 100 stolen files out of an alleged 200GB of data stolen during the attack.

That data includes first names and surnames, addresses, dates of birth, Medicare numbers, policy numbers, phone numbers, and some claims data. The claimed data includes the location of where a customer received medical services, and codes relating to their diagnosis and procedures.

Other uniquely identifiable personal information such as passport numbers with respect to international student policies have also been accessed, but Medibank assured that it found no evidence that direct debit details have been breached.

Medibank customers are advised to stay vigilant for any phishing or smishing scams, with the company pledging free identity monitoring services and financial support for those who are in a uniquely vulnerable position as a result of this crime.

Following a series of high-profile and damaging data breaches that hit several Australian firms in the past few weeks, the government is working to introduce stricter data protection laws.

A proposal published by the Australian Government on Saturday for the new Privacy Legislation Amendment Bill 2022 aims to:

  • Increase privacy breach penalties from $2.22 million AUD to $50 million AUD,
  • or three times the value of any benefit obtained through the misuse of information, if greater,
  • or 30% of a company’s adjusted turnover in the relevant period, if greater.

The new Privacy Legislation Amendment Bill 2022 also seeks to entrust the Australian Information Commissioner with more powers to resolve privacy breaches.

Image Credits : The West Australian

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Zoom patches high-severity flaw in macOS client

Previous article

See Tickets data breach went undetected for 2.5 years

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *