Hacker releases Australian health insurer’s customer data

Nov 8, 2022, 2:53 AM | Updated: Nov 9, 2022, 1:42 am

A computer and phone display pages from the Medibank Private website in Sydney, Tuesday, Nov. 8, 20...

A computer and phone display pages from the Medibank Private website in Sydney, Tuesday, Nov. 8, 2022. Medibank client data was published by an extortionist Wednesday, Nov. 9, including details of individuals' medical procedures, after Australia’s largest health insurer refused to pay a ransom for the personal records of almost 10 million current and former customers. (AP Photo/Rick Rycroft)

(AP Photo/Rick Rycroft)

CANBERRA, Australia (AP) — Client data from Medibank, Australia’s largest health insurer, was released by an extortionist on Wednesday, including details of HIV diagnoses and drug abuse treatments, after the company refused to pay a ransom for the personal records of almost 10 million current and former customers.

The material released on the dark web appeared to be a sample of the data that Medibank has determined was stolen last month, the company said. Medibank expects the thief will continue releasing data.

“This is a criminal act designed to harm our customers and cause distress,” Medibank CEO David Koczkar said in a statement that reiterated a previous apology to customers.

“We take seriously our responsibility to safeguard our customers and we stand ready to support them,” he added.

The data included what the thief called a “naughty list” of more than 100 names. Among them were patients who had contracted HIV and others who were treated for addictions to drugs and alcohol and for mental health problems.

One of the exposed customers contacted by Nine News television responded with anger toward Medibank.

“Letting customers discover their most sensitive information imaginable has been published and hearing it on the news, Medibank’s response has been pathetic,” the unidentified man, whose image was not broadcast, told Nine.

Cybersecurity Minister Clare O’Neil, who is a Medibank customer and has had personal data stolen, urged social and traditional media companies to prevent their platforms from being used to share people’s stolen medical histories.

“If you do so, you will be aiding and abetting the scumbags who are at the heart of these criminal acts and I know that you would not do that to your own country and your own citizens,” O’Neil told Parliament.

She said the number of people whose medical information has been released was “small at this stage.”

“But I want the Australian people to understand that that is likely to change, and we are going through a difficult period now that may last for weeks, possibly months, not days and hours,” O’Neil added.

Prime Minister Anthony Albanese, who is also a Medibank customer, welcomed the company’s refusal to pay the hacker to have the records returned.

“This is really tough for people. I’m a Medibank Private customer as well and it will be of concern that some of this information has been put out there,” Albanese told reporters, referring to a Medibank brand.

“The company has followed the guidelines effectively, the advice, which is to not engage in a ransom payment. If you go down this road, then you end up with more difficulties potentially across a wider range,” Albanese said.

The thieves had reportedly threatened to expose the diagnoses and treatments of high-profile customers unless a ransom of an undisclosed amount was paid, but Medibank decided there was “only a limited chance” that a payment would prevent the data from being published.

A blogger using the name “Extortion Gang” posted Monday night on the dark web that “data will be publish in 24 hours.”

Medibank this week updated its estimate of the number of people whose personal information was stolen from 4 million two weeks ago to 9.7 million. The stolen data includes health claims of almost 500,000 people including diagnoses and treatments, the company said.

The theft of the personal records of 9.8 million customers of Optus, Australia’s second-largest wireless telecommunications carrier, that was discovered on Sept. 21 prompted the government to promise heftier penalties for corporations that fail to protect private data.

The House of Representatives on Wednesday passed an urgent bill that would increase penalties for serious breaches of the Privacy Act from 2.2 million Australian dollars ($1.4 million) to AU$50 million ($32 million) or more.

The government hopes the bill will be passed by the Senate and become law this month.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Eugene and Linda Lamie, of Homerville, Ga., sit by the grave of their son U.S. Army Sgt. Gene Lamie...

Associated Press

Biden marks Memorial Day lauding generations of fallen US troops who ‘dared all and gave all’

President Joe Biden lauded the sacrifice of generations of U.S. troops who died fighting for their country as he marked Memorial Day with the traditional wreath-laying ceremony at Arlington National Cemetery.

11 hours ago

OpenAI's CEO Sam Altman, the founder of ChatGPT and creator of OpenAI gestures while speaking at Un...

Associated Press

ChatGPT maker downplays fears they could leave Europe over AI rules

OpenAI CEO Sam Altman on Friday downplayed worries that the ChatGPT maker could exit the European Union

1 day ago

File - Alphabet CEO Sundar Pichai, left, and OpenAI CEO Sam Altman arrive to the White House for a ...

Associated Press

Regulators take aim at AI to protect consumers and workers

As concerns grow over increasingly powerful artificial intelligence systems like ChatGPT, the nation’s financial watchdog says it’s working to ensure that companies follow the law when they’re using AI.

3 days ago

FILE - A security surveillance camera is seen near the Microsoft office building in Beijing, July 2...

Associated Press

Microsoft: State-sponsored Chinese hackers could be laying groundwork for disruption

State-backed Chinese hackers have been targeting U.S. critical infrastructure and could be laying the technical groundwork for the potential disruption of critical communications between the U.S. and Asia during future crises, Microsoft said Wednesday.

4 days ago

FILE - President Joe Biden speaks in the East Room of the White House, May 17, 2023, in Washington....

Associated Press

White House unveils new efforts to guide federal research of AI

The White House on Tuesday announced new efforts to guide federally backed research on artificial intelligence

5 days ago

FILE - The Capitol stands in Washington D.C. (AP Photo/J. Scott Applewhite, File)Credit: ASSOCIATED...

Associated Press

What it would mean for the economy if the US defaults on its debt

If the debt crisis roiling Washington were eventually to send the United States crashing into recession, America’s economy would hardly sink alone.

6 days ago

Sponsored Articles

Internet Washington...

Major Internet Upgrade and Expansion Planned This Year in Washington State

Comcast is investing $280 million this year to offer multi-gigabit Internet speeds to more than four million locations.

Compassion International...

Brock Huard and Friends Rally Around The Fight for First Campaign

Professional athletes are teaming up to prevent infant mortality and empower women at risk in communities facing severe poverty.

Emergency Preparedness...

Prepare for the next disaster at the Emergency Preparedness Conference

Being prepared before the next emergency arrives is key to preserving businesses and organizations of many kinds.

SHIBA volunteer...

Volunteer to help people understand their Medicare options!

If you’re retired or getting ready to retire and looking for new ways to stay active, becoming a SHIBA volunteer could be for you!

safety from crime...

As crime increases, our safety measures must too

It's easy to be accused of fearmongering regarding crime, but Seattle residents might have good reason to be concerned for their safety.

Comcast Ready for Business Fund...

Ilona Lohrey | President and CEO, GSBA

GSBA is closing the disparity gap with Ready for Business Fund

GSBA, Comcast, and other partners are working to address disparities in access to financial resources with the Ready for Business fund.

Hacker releases Australian health insurer’s customer data