Hacker threatens to release data stolen from 9.7m Medibank customers

Medibank calls the threat a "distressing development"

Add bookmark
Hacker threatens to release data stolen from 9.7m Medibank customers

A threat to release 200GB worth of data stolen from Australian health insurance company Medibank has been posted to a site backed by Russian ransomware group, REvil.

The threat comes after Medibank made a public statement that it would not be paying the ransom demanded by the hacker.

In the message, the supposed hacker quotes Confuscious, implying Medibank is making a "mistake" by not paying the ransom. The malicious actor then said that they would release the data within the next 24 hours, and advised readers to "sell Medibank stock". 

Medibank share prices have decreased by 21 percent from AU$3.51 to AU$2.78 in the last three weeks, after the extent of the data breach was revealed.

Medibank called the threats to release the data a "distressing development".

David Koczkar, CEO of Medibank, apologized to those affected by the breach, saying: "We unreservedly apologise to our customers. We take seriously our responsibility to safeguard our customers and support them. The weaponisation of their private information is malicious, and it is an attack on the most vulnerable members of our community."

When the threat became known to the company, Medibank contacted all customers to warn them of the possibility of scams and direct phishing attacks. The company also urged all those who were victims of cybercrime or had been contacted by someone claiming to have their data to report it to the Australian Cyber Security Centre.

Medibank continues to work with the Australian Government, including the Australian Cyber Security Centre and the Australian Federal Police to investigate the cyber attack and prevent the share and selling of its customer's data.


Upcoming Events

16th Automotive Cybersecurity Summit 2026

March 18 - 19, 2026

Sheraton Ann Arbor Hotel, Ann Arbor, Michigan

16th Automotive Cybersecurity Summit 2026

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"636935bb7746201f8c7ff6bf","name":"Medibank refuses pay ransom after 9.7m customers\u2019 details stolen","description":"The company said there was a \u201climited chance\u201d paying the ransom would prevent the release of the data","file":null,"url":"\/attacks\/news\/medibank-refuses-pay-ransom-after-97m-customers-details-stolen"},{"id":"634fe972c5c9f27fbf0907be","name":"Medibank is latest Australian company to suffer cyber security incident","description":"Hackers have threatened to release customer data if their demands are not met","file":null,"url":"\/attacks\/news\/medibank-is-latest-australian-company-to-suffer-cyber-security-incident"},{"id":"630f1f657e0c653b956d1017","name":"Student loan data breach leaks 2.5 million social security numbers","description":"Bad actors may have gained access to millions of users\u2019 information between June and July","file":null,"url":"\/attacks\/news\/student-loan-data-breach-leaks-25-million-social-security-numbers"},{"id":"633c29fa2d36014b536f4a98","name":"Data breach sees Telstra employees\u2019 details posted online","description":"The details of 30,000 employees have been shared on a hacking forum","file":null,"url":"\/attacks\/news\/data-breach-sees-telstra-employees-details-posted-online"},{"id":"60e84adad1d92e357624a033","name":"IOTW: REvil Ransomware Attack Hits Potentially Thousands of Businesses","description":null,"file":null,"url":"\/executive-decisions\/articles\/iotw-revil-ransomware-attack-hits-potentially-thousands-of-businesses"}],"featured_content_portal_embedded":null}" >