AP

Extortionist threatens to publish Australian customer data

Nov 7, 2022, 5:20 AM | Updated: 7:39 pm

A computer and phone display pages from Medibank Private in Sydney, Tuesday, Nov. 8, 2022. Health i...

A computer and phone display pages from Medibank Private in Sydney, Tuesday, Nov. 8, 2022. Health insurer Medibank on Monday ruled out paying ransom for stolen customer data while a purported hacker responded on Tuesday by setting a 24-hour deadline for the release that data including personal medical histories. (AP Photo/Rick Rycroft)

(AP Photo/Rick Rycroft)

CANBERRA, Australia (AP) — An extortionist has threatened to make Medibank customer data public within 24 hours after Australia’s largest health insurer refused to pay a ransom for the personal records of almost 10 million current and former customers.

Medibank on Monday ruled out paying ransom for the stolen data. The theft was reported to police Oct. 19 when trade in the company’s shares was halted for a week.

The thieves had reportedly threatened to expose the diagnoses and treatments of high-profile customers unless a ransom of an undisclosed sum was paid.

“Based on the extensive advice we have received from cybercrime experts, we believe there is only a limited chance paying a ransom would ensure the return of our customers’ data and prevent it from being published,” Medibank CEO David Koczkar said in a statement.

“In fact, paying could have the opposite effect and encourage the criminal to directly extort our customers and there is a strong chance that paying puts more people in harm’s way by making Australia a bigger target,” Koczkar added.

A blogger using the name “Extortion Gang” posted Monday night on the dark web that “data will be publish (sic) in 24 hours.”

“P.S. I recommend to sell medibank (sic) stocks,” the blog added.

The post did not include data samples that could prove the author held the data. But Medibank on Tuesday took the threat seriously.

“We knew the publication of data online by the criminal could be a possibility, but the criminal’s threat is still a distressing development for our customers,” Koczkar said.

Koczkar urged customers to remain vigilant and warned that the criminal could contact them directly.

Medibank this week updated its estimate of the number of people whose personal information had been stolen from 4 million two weeks ago to 9.7 million. The stolen data included health claims of almost 500,000 people including diagnoses and treatments, the company said.

“The weaponization of their private information is malicious and it is an attack on the most vulnerable members of our society,” Koczkar said.

Cybersecurity Minister Clare O’Neil welcomed Medibank’s stance, saying its refusal to pay a ransom was in line with her government’s advice.

Medibank revealed this week that a hacker stole a company employee’s username and password to access the customer database.

At least two legal firms say they are investigating a potential class-action lawsuit against Medibank for failing to protect customer data.

The price of Medibank shares fell almost 3% in early trade Tuesday on the Australian Security Exchange following threats of data publication and lawsuits.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

FILE - A person shows their scan card for their personal selection numbers for a ticket for a Power...

L.B. Gilbert

$1.2 billion Powerball drawing nears after 11 weeks without a winner

A $1.2 billion Powerball jackpot will again be up for grabs Wednesday night after an 11-week stretch without a big winner

3 hours ago

FILE - A man walks through wildfire wreckage in Lahaina, Hawaii, Aug. 11, 2023. Federal authorities...

Associated Press

Cleanup from Maui fires complicated by island’s logistical challenges, cultural significance

Cleanup of areas destroyed in the Maui wildfires could end up being one of the most complex to date, federal officials said, given the island's significant cultural sites, its rich history including a royal residence and possibly remains of people who died in the disaster.

10 hours ago

Former President Donald Trump sits in the courtroom at New York Supreme Court, Monday, Oct. 2, 2023...

MICHAEL R. SISAK, JENNIFER PELTZ AND BOBBY CAINA CALVAN

New York judge issues limited gag order after Trump makes disparaging post about court clerk

A New York judge imposed a limited gag order on defendant Donald Trump Tuesday after the former president disparaged a key court staffer during his civil business fraud trial.

1 day ago

Microsoft CEO Satya Nadella speaks during the introduction of the integration of Microsoft Bing sea...

Suman Naishadham, Associated Press

Microsoft CEO says unfair practices by Google led to its dominance as a search engine

Microsoft CEO Satya Nadella said Monday that unfair tactics used by Google led to its dominance as a search engine, tactics that in turn have thwarted his company’s rival program, Bing.

1 day ago

This undated photo provided by the Federal Bureau of Investigation's Portland Field Office shows a ...

Associated Press

Man accused of kidnapping Seattle woman, kidnapping charges in separate case

A man accused of abducting a woman in Seattle, driving her hundreds of miles to his home in Oregon and locking her in a makeshift cinder block cell 

2 days ago

A person browses offerings in the Raven's Nest Treasure shop in Pike Place Market, Dec. 10, 2021, i...

Associated Press

Man who faked Native American heritage to sell his art in Seattle sentenced to probation

A Washington state man who falsely claimed Native American heritage to sell his artwork at downtown Seattle galleries was sentenced Wednesday to federal probation and community service.

2 days ago

Sponsored Articles

Swedish Cyberknife...

September is Prostate Cancer Awareness Month

September is a busy month on the sports calendar and also holds a very special designation: Prostate Cancer Awareness Month.

Ziply Fiber...

Dan Miller

The truth about Gigs, Gs and other internet marketing jargon

If you’re confused by internet technologies and marketing jargon, you’re not alone. Here's how you can make an informed decision.

Education families...

Education that meets the needs of students, families

Washington Virtual Academies (WAVA) is a program of Omak School District that is a full-time online public school for students in grades K-12.

Emergency preparedness...

Emergency planning for the worst-case scenario

What would you do if you woke up in the middle of the night and heard an intruder in your kitchen? West Coast Armory North can help.

Innovative Education...

The Power of an Innovative Education

Parents and students in Washington state have the power to reimagine the K-12 educational experience through Insight School of Washington.

Medicare fraud...

If you’re on Medicare, you can help stop fraud!

Fraud costs Medicare an estimated $60 billion each year and ultimately raises the cost of health care for everyone.

Extortionist threatens to publish Australian customer data