Australians are on high alert after a hacking syndicate threatened to release the personal details of nearly 10 million individuals following a major data breach of the country’s largest private health insurer Medibank.
Hackers threatened to begin leaking information in the next 24 hours while suggesting shareholders begin selling Medibank stocks.
Medibank Apologises
In a media update on Tuesday, Medibank CEO David Koczkar said the news was “distressing.”“Customers should remain vigilant. We knew the publication of data online by the criminal could be a possibility, but the criminal’s threat is still a distressing development for our customers,” Koczkar said.
“We unreservedly apologise to our customers. We take seriously our responsibility to safeguard our customers and support them. The weaponisation of their private information is malicious, and it is an attack on the most vulnerable members of our community.”
In addition, the health claims data for 160,000 Medibank, 300,000 ahm, and 20,000 international customers were also breached. Some customers were receiving medical services such as diagnosis and procedures.
Meanwhile, credit card and banking details, as well as data on health claims for dental, physiotherapy, optical, and psychology, were not breached, the company said.
Originally designed to deal with the pandemic, the mechanism allows the government to bring together agencies across the Australian government, states and territories, and the private sector to help coordinate a response.
Minister Backs Decision Not to Pay Ransom
Cyber Security Minister Clare O'Neil has backed the decision by Medibank not to pay the ransom, saying it will encourage further behaviour.“Cyber criminals cheat, lie and steal. Paying them only fuels the ransomware business model,” she said. “They commit to undertaking actions in return for payment, but so often re-victimise companies and individuals.”
Further Suspicions of Russian Syndicate Links
Cybersecurity analysts have noted several coincidences between the actions of the group and known Russian hacking syndicates.Brett Callow, threat analyst at Emsisoft, said a meme used in the initial ransom message was posted earlier by a group called @Cyberknow20 on Twitter.