AP

Hacker releases Australian health insurer’s customer data

Nov 8, 2022, 2:53 AM | Updated: Nov 9, 2022, 1:42 am

A computer and phone display pages from the Medibank Private website in Sydney, Tuesday, Nov. 8, 20...

A computer and phone display pages from the Medibank Private website in Sydney, Tuesday, Nov. 8, 2022. Medibank client data was published by an extortionist Wednesday, Nov. 9, including details of individuals' medical procedures, after Australia’s largest health insurer refused to pay a ransom for the personal records of almost 10 million current and former customers. (AP Photo/Rick Rycroft)

(AP Photo/Rick Rycroft)

CANBERRA, Australia (AP) — Client data from Medibank, Australia’s largest health insurer, was released by an extortionist on Wednesday, including details of HIV diagnoses and drug abuse treatments, after the company refused to pay a ransom for the personal records of almost 10 million current and former customers.

The material released on the dark web appeared to be a sample of the data that Medibank has determined was stolen last month, the company said. Medibank expects the thief will continue releasing data.

“This is a criminal act designed to harm our customers and cause distress,” Medibank CEO David Koczkar said in a statement that reiterated a previous apology to customers.

“We take seriously our responsibility to safeguard our customers and we stand ready to support them,” he added.

The data included what the thief called a “naughty list” of more than 100 names. Among them were patients who had contracted HIV and others who were treated for addictions to drugs and alcohol and for mental health problems.

One of the exposed customers contacted by Nine News television responded with anger toward Medibank.

“Letting customers discover their most sensitive information imaginable has been published and hearing it on the news, Medibank’s response has been pathetic,” the unidentified man, whose image was not broadcast, told Nine.

Cybersecurity Minister Clare O’Neil, who is a Medibank customer and has had personal data stolen, urged social and traditional media companies to prevent their platforms from being used to share people’s stolen medical histories.

“If you do so, you will be aiding and abetting the scumbags who are at the heart of these criminal acts and I know that you would not do that to your own country and your own citizens,” O’Neil told Parliament.

She said the number of people whose medical information has been released was “small at this stage.”

“But I want the Australian people to understand that that is likely to change, and we are going through a difficult period now that may last for weeks, possibly months, not days and hours,” O’Neil added.

Prime Minister Anthony Albanese, who is also a Medibank customer, welcomed the company’s refusal to pay the hacker to have the records returned.

“This is really tough for people. I’m a Medibank Private customer as well and it will be of concern that some of this information has been put out there,” Albanese told reporters, referring to a Medibank brand.

“The company has followed the guidelines effectively, the advice, which is to not engage in a ransom payment. If you go down this road, then you end up with more difficulties potentially across a wider range,” Albanese said.

The thieves had reportedly threatened to expose the diagnoses and treatments of high-profile customers unless a ransom of an undisclosed amount was paid, but Medibank decided there was “only a limited chance” that a payment would prevent the data from being published.

A blogger using the name “Extortion Gang” posted Monday night on the dark web that “data will be publish in 24 hours.”

Medibank this week updated its estimate of the number of people whose personal information was stolen from 4 million two weeks ago to 9.7 million. The stolen data includes health claims of almost 500,000 people including diagnoses and treatments, the company said.

The theft of the personal records of 9.8 million customers of Optus, Australia’s second-largest wireless telecommunications carrier, that was discovered on Sept. 21 prompted the government to promise heftier penalties for corporations that fail to protect private data.

The House of Representatives on Wednesday passed an urgent bill that would increase penalties for serious breaches of the Privacy Act from 2.2 million Australian dollars ($1.4 million) to AU$50 million ($32 million) or more.

The government hopes the bill will be passed by the Senate and become law this month.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Image: Former President Donald Trump and his lawyer Todd Blanche appear at Manhattan criminal in Ne...

Associated Press

Police to review security outside courthouse hosting Trump trial after man sets himself on fire

Crews rushed away a person after fire was extinguished outside where jury selection was taking place in the Donald Trump criminal trial.

4 hours ago

Photo: Homeland Security Secretary Alejandro Mayorkas is sworn-in before the House Committee on Hom...

the MyNorthwest Staff with wire reports

Senate dismisses two articles of impeachment against Homeland Security secretary, ends trial

The Senate dismissed impeachment charges against Homeland Security Secretary Alejandro Mayorkas, as Republicans pushed to remove him.

2 days ago

idaho gender-affirming care...

Associated Press

Supreme Court allows Idaho to enforce its ban on gender-affirming care for transgender youth

The Supreme Court is allowing Idaho to enforce its ban on gender-affirming care for transgender youth while lawsuits over the law proceed.

3 days ago

Image: Former President Donald Trump speaks to the press in Manhattan state court in New York City ...

Associated Press

Trump’s hush money trial gets underway; 1st day ends without any jurors selected

The historic hush money trial of Donald Trump got underway Monday with the arduous process of selecting a jury to hear the case.

4 days ago

Photo: Israeli Iron Dome air defense system launches to intercept missiles fired from Iran, in cent...

Tia Goldenberg and Josef Federman, The Associated Press

Israel is quiet on next steps against Iran — and on which partners helped shoot down missiles

On Sunday, Israel's leaders credited an international military coalition with helping thwart a direct attack from Iran.

5 days ago

Early phases of Iran's drone attack against Israel. (Photo: Getty Images)...

Associated Press

The Latest | Iran launches its first direct military attack against Israel

Iran launched its first full-scale military attack against Israel on Saturday, sending drones toward Israel.

6 days ago

Hacker releases Australian health insurer’s customer data