← Case Files · The Breach Files

2022 · Health insurance

Medibank, 2022: the company said no, and the data went up anyway

Case file · 4 min read · Published 14 September 2026

People affected
9.7 million current and former customers; health claims data for about 480,000
When it happened
August – October 2022
Made public
October 2022
How they got in
Stolen credentials belonging to a third-party IT contractor, with no multi-factor authentication
Attributed to
Actors linked to the REvil ransomware ecosystem; Australia sanctioned Aleksandr Ermakov in 2024
What it cost
Regulatory proceedings, class actions, and a A$250 million capital requirement imposed by the prudential regulator

What was exposed: Names · Dates of birth · Addresses · Phone numbers · Medicare and policy numbers · Health claims data including procedures and diagnoses

Three weeks after Optus, Australia had a second national breach — and a much worse one. Medibank, the country's largest private health insurer, lost the records of 9.7 million current and former customers, including the claims histories of around 480,000. When it refused to pay, the attackers published the data in tranches, organised by diagnosis.

What happened

The intrusion began in August 2022 with credentials belonging to a third-party IT services contractor. Those credentials were not protected by multi-factor authentication, so whoever held the password held the access. They were used to reach Medibank's internal network, where the attackers moved through systems and eventually copied roughly 200 gigabytes of data.

Medibank detected unusual activity in October and initially reported that no customer data appeared to have been taken. That position did not survive the week: the attackers contacted the company with a sample, and the disclosure was revised upward repeatedly until it covered essentially the entire customer base, past and present.

One missing control, again. The credential had no second factor. It is the same finding as Change Healthcare two years later and Colonial Pipeline the year before: an account belonging to a contractor or a legacy service, reachable from outside, protected by a password alone. The reason this keeps happening is not ignorance — every one of these organisations had an MFA programme. It is that the programme covered employees and missed the accounts at the edges.

The extortion, and the refusal

The attackers demanded a ransom, reported at around US$10 million and later reduced. Medibank's chief executive announced that the company would not pay, on the reasoning that payment would not guarantee return or deletion of the data and would encourage further attacks on Australian organisations. The federal government publicly backed the decision.

The attackers responded by publishing. Not all at once — in batches, over weeks, on a dark web site, with the files given names calculated to cause the maximum distress. One release was labelled for customers whose claims related to termination of pregnancy. Others grouped people by treatment for mental health and substance use.

This was not monetisation. Nobody buys that data. It was pressure applied through the customers, and it worked in the sense that it dominated Australian news coverage for weeks — but Medibank did not reverse its decision.

Why health claims data is the worst category

Every other entry in this archive involves data that can, eventually, be neutralised. Cards get cancelled. Passwords get changed. Even passport numbers get reissued.

A claims record says that a named person had a specific procedure on a specific date. It cannot be revoked, corrected or replaced, because it is true. The harm is not fraud; it is the fact of other people knowing — an employer, a family member, a community. For customers whose treatment involved reproductive health, mental health, addiction or HIV, the publication was the harm, complete on the day it happened.

That is what puts Medibank in the same category as Ashley Madison rather than with the credential dumps, and it is why health data attracts the severity weighting it does.

The timeline

  1. August 2022 — A contractor's credentials, without MFA, are used to access Medibank's network.
  2. August–October — Around 200GB of data is copied out.
  3. 12 October 2022 — Medibank detects unusual activity and takes systems offline.
  4. 19–26 October — The scope is revised repeatedly; the attackers provide samples; the full customer base is confirmed as affected.
  5. 7 November 2022 — Medibank announces it will not pay the ransom.
  6. 9 November onwards — Data is published in tranches on a dark web site, grouped by sensitive treatment category.
  7. June 2023 — The prudential regulator imposes a A$250 million capital adjustment.
  8. January 2024 — Australia imposes its first autonomous cyber sanctions, naming Aleksandr Ermakov.
  9. June 2024 — The privacy regulator commences civil penalty proceedings.

What it changed

Australia took a national position on ransom payments. Medibank is the reference case in every subsequent Australian discussion of whether to pay, and it shaped the ransomware reporting obligations introduced afterwards. The uncomfortable corollary — that refusing means the customers bear the consequence — is now argued openly rather than avoided.

Contractor access became the named weak point. Between Optus and Medibank, Australian regulators landed on the same conclusion within a month: the perimeter that matters is not the corporate network, it is every credential that can reach it, including those held by suppliers.

Sanctions entered the toolkit. Naming and sanctioning an individual was a deliberate shift from silence. It does not produce a trial, but it constrains the named person's ability to move money and signals that attribution work continues after the news cycle ends.

If you were a Medibank customer

  1. Nothing you do removes published claims data. That is a hard sentence, and it is the truthful one. What remains controllable is everything the data enables next.
  2. Expect targeted extortion and scams. Australians in the file received messages quoting their own claims history. That specificity is a sign of the leak, not a sign of legitimacy — no insurer or agency will demand payment to suppress your records.
  3. Protect the identity layer. Medicare and policy numbers were included; a credit ban and a port-out lock on your phone service are the two cheap controls that matter.
  4. Report extortion attempts to your national cybercrime service rather than engaging. Free counselling services were made available in Australia specifically for people affected by this breach, and using them is a reasonable response to a genuinely distressing situation.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

Why did Medibank refuse to pay?

The company said publicly that paying would not guarantee the data was returned or deleted, and would make Australian organisations a more attractive target. The Australian government supported the position. It is the correct analysis in the general case, and it also meant the customers in the file bore the consequences of a decision made on behalf of everyone else — which is the uncomfortable part nobody enjoys stating.

What made this breach different from Optus?

Optus lost identity documents, which can be replaced. Medibank lost health claims data — records of treatment, including procedures people had chosen not to tell anyone about. There is no reissue process for that. The attackers understood it, and published the most sensitive categories first.

How did the attackers get in?

Through credentials belonging to a third-party IT services contractor. The credentials did not have multi-factor authentication, so possession of the password was sufficient. They were used to reach Medibank's network, and roughly 200GB of data was taken over several weeks before detection.

Was anyone held responsible?

In January 2024 Australia used its cyber sanctions powers for the first time, against Aleksandr Ermakov, a Russian national it named as involved. Sanctions make it a criminal offence to provide him assets and freeze what can be reached. He has not stood trial. Separately, the privacy regulator commenced civil penalty proceedings against Medibank.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →