In October 2022, Medibank, one of Australia's largest private health insurers, disclosed that a cybercriminal had stolen about 520GB of data. The breach affected around 9.7 million current and former Medibank, ahm and international customers and representatives, including people whose sensitive health claims information was exposed.
Through its Medibank and ahm brands, the group insures millions of people across Australia.
The weaknesses that contributed to this breach were not unusual. According to allegations filed by the Australian Information Commissioner, an employee of a Medibank IT contractor saved Medibank credentials in his browser profile on a work computer. When he signed into the same browser profile on a personal computer, the credentials synchronised to that device and were later stolen by malware.
A cybercriminal then used the compromised credentials to access Medibank’s remote-access VPN, which did not require MFA for that login method. Medibank’s security software raised alerts about suspicious activity, but they were delayed to triage for weeks.
Three basic controls failed in a large organisation. Every one of them could be missing in small businesses too.
On 13 October 2022, Medibank disclosed unusual activity on its network and initially said there was no evidence that customer data had been removed. On 19 and 22 October, an attacker contacted Medibank and supplied sample files. Medibank later confirmed that information connected to around 9.7 million people had been stolen. The OAIC alleges that about 520GB of data was exfiltrated between late August and 13 October 2022.
The attacker demanded US$10 million. Medibank refused to pay, explaining that payment could not guarantee the return or deletion of the data and might encourage further extortion.
From 9 November to 1 December 2022, stolen information was published on a dark-web leak site in stages, fully releasing the dataset. Published files included highly sensitive health claims information, including records about HIV, drug and alcohol treatment, mental health, and abortions. Australian authorities later attributed the attack to Russian national Aleksandr Ermakov, who was associated with the REvil cybercrime group.
In January 2024, Australia used its cyber sanctions framework for the first time and designated Aleksandr Ermakov for his role in the Medibank breach, imposing targeted financial sanctions and a travel ban. Dealing with a designated person or their assets can be a criminal offence carrying severe penalties, including up to 10 years’ imprisonment for an individual.
| Date | Event |
|---|
| Prior to 7 August 2022 | A contractor employee saved Medibank credentials in a browser profile on a work computer. The credentials were later synchronised to his personal computer. |
| Around 7 August 2022 | Malware on the personal computer stole the Medibank credentials. |
| 12 August 2022 | The attacker tested the stolen admin credentials against Medibank’s Microsoft Exchange server. |
| Around 23 August 2022 | The attacker first logged in to Medibank’s GlobalProtect VPN, with no MFA required. |
| 24 - 25 August 2022 | Medibank’s security software generated alerts, sending them to an IT operations mailbox. The OAIC alleges they were not appropriately triaged or escalated. |
| 25 August - 13 October 2022 | The attacker accessed Medibank's internal systems and exfiltrated about 520GB of data. |
| 11 October 2022 | Medibank triaged a high-severity alert and engaged its incident-response partner. |
| 13 October 2022 | Medibank publicly discloses the incident, initially stating that there was no evidence that customer data had been removed. |
| 19 and 22 October 2022 | The attacker contacted Medibank and supplied sample files with stolen data. |
| 7 November 2022 | Medibank confirmed the scale of the breach - 9.7 million people - and publicly refused to pay the ransom. |
| 9 November - 1 December 2022 | Stolen information was published on the dark web in stages, ending with the full 520GB released. |
| 27 June 2023 | APRA announced a $250M increase in Medibank’s capital adequacy requirement until remediation was completed to APRA’s satisfaction. |
| 23 January 2024 | Australia imposed its first cyber sanction, designating Aleksandr Ermakov for his role in the breach. |
| 5 June 2024 | The OAIC files civil penalty proceedings in the Federal Court over alleged failure to take reasonable steps to protect personal information. |
| As of July 2026 | The OAIC proceedings continued, and the Medibank class action remained listed as open in the Federal Court. |
Based on the OAIC’s allegations and Medibank’s public updates, the incident began with stolen credentials, remote access without MFA and an account with extensive privileges. Here’s how the hacker gained access:
- Credential theft through infostealer malware. The Medibank credentials saved in a contractor employee’s browser profile were synchronised to his personal computer and were stolen by malware.
- Remote access without MFA. The VPN was configured to accept a username and password and did not require MFA.
- Broad access and delayed escalation. The compromised admin account could access most Medibank systems. The OAIC alleges that security alerts were generated from 24 August onwards but were not appropriately triaged or escalated, allowing the hacker to locate and exfiltrate about 520GB of data over seven weeks.
The publicly available evidence describes a data-theft and extortion incident rather than ransomware with encrypted systems. The attacker simply used valid credentials to access systems and steal data, then demanded payment to prevent publication.
- No MFA on remote access. A username and password were enough for the hacker to access Medibank’s systems. MFA would have added an important barrier and may have prevented or limited the initial access.
- An unmanaged personal device. Corporate credentials were synchronised to a personal computer outside Medibank’s managed environment, where malware stole them.
- Poor alert response. Detection software generated alerts, but the process for reviewing, triaging and escalating them did not work as intended.
- One account had very broad access. The service-desk account had access to "most, if not all, systems", so one stolen credential became keys to the whole building.
- Known weaknesses were not fixed in time. The OAIC alleges Medibank knew about the security gaps, including the MFA gap, through its cyber security audits, and failed to fix them in time.
- Direct response and remediation costs reached tens of millions of dollars across several financial years, before any final litigation outcomes.
- Blackmail and ransom demands: Medibank refused the US$10M ransom, and the stolen data was later published.
- APRA's $250 million capital adequacy adjustment: This was not a fine, but it required Medibank to hold additional capital until APRA was satisfied with the remediation program.
- Regulatory and legal scrutiny: The ongoing OAIC civil penalty proceedings and a Federal Court class action, still listed as open.
- Harm to affected people:: Published information included identity details and sensitive health claims data, creating risks of fraud, scams, blackmail, identity theft and emotional distress for the affected individuals.
- Wider impact:: The breach contributed to national debate about privacy, cyber security and ransomware. In 2024, Australia imposed its first cyber sanction in response to the incident.
- Reputational damage: The incident affected customer trust and kept Medibank under public, regulatory and legal scrutiny for years.
Although the breach exposed serious weaknesses, and early breach figures changed as the incident investigation progressed, several aspects of Medibank’s incident response are worth recognising:
- Medibank provided frequent public updates as the breach scope became clearer.
- It also notified regulators and law-enforcement agencies.
- Medibank engaged external cyber incident-response specialists.
- It refused to pay ransom, aligning with the Australian Government view.
- Medibank also offered support measures, including identity monitoring and hardship support for affected customers
- It also committed to remediation and security investment.
- Mandatory MFA. If one control defines this breach, it's this. Enforce mandatory MFA for VPNs, emails, cloud systems, admin accounts, contractor accounts and third-party support access.
- Properly manage contractor access. Administrator access should be role-based rather than universal across internal systems. Privileged access should only be granted when required, time-limited, approved, monitored and reviewed regularly. Contractors should not have privileged access to all systems and databases.
- Require managed devices for corporate access. Personal or unmanaged devices should not access sensitive systems unless strong technical controls are in place. Access should be limited to devices that are managed, compliant, patched and monitored.
- Apply least privilege. Give each user only the access needed for their role. Review privileged access regularly and remove it when it is no longer required.
- Strengthen browser and credential security. Do not allow corporate credentials to be stored in browsers. Use an approved password manager and configure managed browsers to control password saving and profile synchronisation.
- Every alert needs an owner. Decide who acts on warnings from your antivirus, bank and software, and how they should respond to them.
- Reduce sensitive data exposure. Keep only the information you need, restrict access, separate high-risk data, encrypt it where appropriate, and monitor unusual access or large data transfers.
- Network segmentation. Consider separating your network into secure zones to reduce access to sensitive data.
- Act on cyber security findings. The OAIC alleges that Medibank's cyber security audits flagged the MFA gap. Treat audit findings, penetration-test results and insurer questionnaires as actions with owners, deadlines and management oversight.
- Train employees and contractors. Cover secure credential storage, approved password managers, MFA methods, risk of browser synchronisation, phishing methods, incident reporting and how to correctly respond to credential theft attempts.
While the publicly available information does not provide every technical detail of the Medibank attack, the incident can still be examined using established cyber security frameworks. This can help turn the incident into a structured set of lessons.
- Credentials from Web Browsers (T1555.003): The OAIC alleges that Medibank credentials saved in a contractor’s work browser profile were synchronised to a personal computer and later stolen by information-stealing malware.
- External Remote Services (T1133): The attacker allegedly used the stolen credentials to connect to Medibank systems through its GlobalProtect VPN.
- Valid Accounts (T1078): The attacker used an active Medibank administrator account that allowed the login to appear similar to authorised activity.
- Data from Information Repositories (T1213): After entering the environment, the attacker allegedly accessed internal systems and databases containing customer identity and health claims information.
- Govern: Assign responsibility for cyber security, privacy and third-party access. Set clear security requirements for contractors and ensure that known audit findings are recorded, prioritised and fixed.
- Identify: Know which accounts have broad access, which devices can connect remotely, where sensitive customer information is stored, and which systems would create the greatest harm if compromised.
- Protect: Require strong MFA for remote and privileged access. Use managed devices, approved password management software, least privilege, network segmentation and controls that limit access to sensitive databases.
- Detect: Monitor VPN access, privileged-account activity, unusual devices, large searches or exports, and suspicious connections between internal systems. Ensure every important alert has an owner and a clearly-defined escalation process.
- Respond: Maintain and test an incident-response plan. It should cover disabling compromised accounts, revoking active sessions, isolating affected systems, investigating alerts, notifying regulators and communicating with affected customers.
- Recover: Restore affected services safely, support affected people, review what went wrong, and improve access controls, monitoring, contractor arrangements, and incident-response procedures.
Although the Essential Eight does not cover every issue seen in this breach, it provides a useful Australian technical baseline. The most relevant to Medibank’s breach strategy include:
- Multi-factor authentication: Require MFA for VPN access, privileged accounts, contractors, and systems holding sensitive information.
- Restrict administrative privileges: Give employees and contractors only the access needed for their work. Use separate privileged accounts, review access regularly, and remove it when it is no longer required.
The Medibank breach is sometimes framed as the work of a sophisticated Russian hacker. But the practical lesson is simpler: browser-synchronised credentials were stolen from a personal device, remote access did not require MFA for the login method used, an admin account had extensive access, and security alerts were not promptly handled.
Small businesses may have fewer IT and security resources, but the same risks still matter. Know who can access your systems, require MFA, use managed devices, limit each account to the minimum access required, control browser synchronisation and make sure every important security alert has an owner.
Use our DIY cyber security health check to review your current controls and identify practical steps to protect your business.
- Office of the Australian Information Commissioner, Civil penalty action against Medibank and the filed concise statement (June 2024).
- Australian Prudential Regulation Authority, APRA takes action against Medibank Private in relation to cyber incident” (27 June 2023).
- Australian Government - Department of Foreign Affairs and Trade, Cyber sanctions in response to Medibank Private cyber attack (23 January 2024).
- Australian Government - Department of Foreign Affairs and Trade, Significant cyber incidents sanctions framework.
- Australian Government - Department of Foreign Affairs and Trade — Guidance Note: Cyber sanctions.
- Federal Court of Australia, Current class actions - McClure v Medibank Private Limited, VID64/2023.
- Medibank, Cybercrime updates published from 13 October to 1 December 2022.
- MITRE ATT&CK Enterprise framework, Credentials from Web Browsers, T1555.003.
- MITRE ATT&CK Enterprise framework, External Remote Services, T1133.
- MITRE ATT&CK Enterprise framework, Valid Accounts, T1078.
- MITRE ATT&CK Enterprise framework, Data from Information Repositories, T1213.
- National Institute of Standards and Technology, NIST Cybersecurity Framework 2.0.
- ASD’s Australian Cyber Security Centre, Essential Eight explained.
- ASD’s Australian Cyber Security Centre, Essential Eight maturity model.