AP

Australian health insurer says data of all customers hacked

Oct 25, 2022, 7:40 AM | Updated: 8:30 pm

People walk past a Medibank branch in Sydney, Wednesday, Oct. 26, 2022. Medibank, Australia's large...

People walk past a Medibank branch in Sydney, Wednesday, Oct. 26, 2022. Medibank, Australia's largest health insurer, said a cybercriminal had hacked the personal data of all its 4 million customers as the government introduced legislation that would increase penalties for companies that fail to protect clients' private information. (AP Photo/Rick Rycroft)

(AP Photo/Rick Rycroft)


              A man walks past a Medibank branch in Sydney, Wednesday, Oct. 26, 2022. Medibank, Australia's largest health insurer, said a cybercriminal had hacked the personal data of all its 4 million customers as the government introduced legislation that would increase penalties for companies that fail to protect clients' private information. (AP Photo/Rick Rycroft)
            
              People walk past a Medibank branch in Sydney, Wednesday, Oct. 26, 2022. Medibank, Australia's largest health insurer, said a cybercriminal had hacked the personal data of all its 4 million customers as the government introduced legislation that would increase penalties for companies that fail to protect clients' private information. (AP Photo/Rick Rycroft)

CANBERRA, Australia (AP) — Australia’s largest health insurer said on Wednesday a cybercriminal had hacked the personal data of all its 4 million customers, as the government introduced legislation that would increase penalties for companies that fail to protect clients’ private information.

Medibank said “significant amounts of health claims data” had also been accessed in the breach, which was reported to police a week ago when trade in the company’s shares was halted.

The thief has demanded ransom and has reportedly threatened to expose the diagnoses and treatments of high-profile customers.

Medibank said its priority was to discover the specific data stolen in relation to each customer and to share that information with those customers.

The company had previously said the breach was thought to be limited to its subsidiary AHM and foreign students.

“Our investigation has now established that this criminal has accessed all our private health insurance customers’ personal data and significant amounts of their health claims data,” Medibank chief executive David Koczkar said in a statement to the Australian Securities Exchange.

“This is a terrible crime – this is a crime designed to cause maximum harm to the most vulnerable members of our community,” Koczkar added, with an apology to customers.

The government has been planning urgent legislative reforms on cybersecurity regulation since a hacker stole the personal data of almost 10 million current and former customers of Optus, Australia’s second-largest wireless telecommunications carrier.

Optus became aware on Sept. 21 that personal data of more than one-third of Australia’s population of 26 million had been stolen.

In introducing amendments to the Privacy Act to Parliament on Wednesday, Attorney-General Mark Dreyfus mentioned both companies and MyDeal, an online retail intermediary that lost the data of 2.2 million customers in a hack revealed two weeks ago.

“As the Optus, Medibank and MyDeal cyberattacks have recently highlighted, data breaches have the potential to cause serious financial and emotional harm to Australians, and this is unacceptable,” Dreyfus told Parliament.

“Governments, businesses and other organizations have an obligation to protect Australians’ personal data, not to treat it as a commercial asset,” Dreyfus added.

The government is critical of companies that amass more customer data than necessary to make money from it in ways unrelated to the services for which the information was provided.

The penalties for serious breaches of the Privacy Act would increase from 2.2 million Australian dollars ($1.4 million) now to AU$50 million ($32 million) under the proposed amendments.

A company could also be fined the value of 30% of its revenues over a defined period if that amount exceeded AU$50 million ($32 million).

Medibank said on Wednesday it did not have cyber insurance and estimated the hack would reduce its earnings by between AU$25 million ($16 million) and AU$35 million ($22 million) by early next year.

The Medicare trading halt was lifted on Wednesday and shares slid more than 14% in early trading.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Microsoft CEO Satya Nadella speaks during the introduction of the integration of Microsoft Bing sea...

Suman Naishadham, Associated Press

Microsoft CEO says unfair practices by Google led to its dominance as a search engine

Microsoft CEO Satya Nadella said Monday that unfair tactics used by Google led to its dominance as a search engine, tactics that in turn have thwarted his company’s rival program, Bing.

6 hours ago

This undated photo provided by the Federal Bureau of Investigation's Portland Field Office shows a ...

Associated Press

Man accused of kidnapping Seattle woman, kidnapping charges in separate case

A man accused of abducting a woman in Seattle, driving her hundreds of miles to his home in Oregon and locking her in a makeshift cinder block cell 

1 day ago

A person browses offerings in the Raven's Nest Treasure shop in Pike Place Market, Dec. 10, 2021, i...

Associated Press

Man who faked Native American heritage to sell his art in Seattle sentenced to probation

A Washington state man who falsely claimed Native American heritage to sell his artwork at downtown Seattle galleries was sentenced Wednesday to federal probation and community service.

1 day ago

File - The Southern University Human Jukebox marching band warms up before the 2023 National Battle...

Associated Press

Federal student loan payments are starting again. Here’s what you need to know

Federal student loan borrowers will need to start making payments again this month after a three-year-plus pause due to the pandemic.

1 day ago

FILE - The U.S. Capitol is seen on Tuesday, June 13, 2023, on Capitol Hill in Washington. Congress ...

Associated Press

Government shutdown averted with little time to spare as Biden signs funding before midnight

The threat of a federal government shutdown suddenly lifted late Saturday as President Joe Biden signed a temporary funding bill to keep agencies open with little time to spare after Congress rushed to approve the bipartisan deal.

2 days ago

tupac shakur...

Rio Yamat and Ken Ritter

Man tied to suspected shooter in Tupac Shakur’s 1996 killing arrested

Tupac Shakur was gunned down when he was 25. He was in a BMW driven by Death Row Records founder Marion “Suge” Knight.

4 days ago

Sponsored Articles

Swedish Cyberknife...

September is Prostate Cancer Awareness Month

September is a busy month on the sports calendar and also holds a very special designation: Prostate Cancer Awareness Month.

Ziply Fiber...

Dan Miller

The truth about Gigs, Gs and other internet marketing jargon

If you’re confused by internet technologies and marketing jargon, you’re not alone. Here's how you can make an informed decision.

Education families...

Education that meets the needs of students, families

Washington Virtual Academies (WAVA) is a program of Omak School District that is a full-time online public school for students in grades K-12.

Emergency preparedness...

Emergency planning for the worst-case scenario

What would you do if you woke up in the middle of the night and heard an intruder in your kitchen? West Coast Armory North can help.

Innovative Education...

The Power of an Innovative Education

Parents and students in Washington state have the power to reimagine the K-12 educational experience through Insight School of Washington.

Medicare fraud...

If you’re on Medicare, you can help stop fraud!

Fraud costs Medicare an estimated $60 billion each year and ultimately raises the cost of health care for everyone.

Australian health insurer says data of all customers hacked