Hacker threatens to release data stolen from 9.7m Medibank customers

Medibank calls the threat a "distressing development"

Add bookmark
Hacker threatens to release data stolen from 9.7m Medibank customers

A threat to release 200GB worth of data stolen from Australian health insurance company Medibank has been posted to a site backed by Russian ransomware group, REvil.

The threat comes after Medibank made a public statement that it would not be paying the ransom demanded by the hacker.

In the message, the supposed hacker quotes Confuscious, implying Medibank is making a "mistake" by not paying the ransom. The malicious actor then said that they would release the data within the next 24 hours, and advised readers to "sell Medibank stock". 

Medibank share prices have decreased by 21 percent from AU$3.51 to AU$2.78 in the last three weeks, after the extent of the data breach was revealed.

Medibank called the threats to release the data a "distressing development".

David Koczkar, CEO of Medibank, apologized to those affected by the breach, saying: "We unreservedly apologise to our customers. We take seriously our responsibility to safeguard our customers and support them. The weaponisation of their private information is malicious, and it is an attack on the most vulnerable members of our community."

When the threat became known to the company, Medibank contacted all customers to warn them of the possibility of scams and direct phishing attacks. The company also urged all those who were victims of cybercrime or had been contacted by someone claiming to have their data to report it to the Australian Cyber Security Centre.

Medibank continues to work with the Australian Government, including the Australian Cyber Security Centre and the Australian Federal Police to investigate the cyber attack and prevent the share and selling of its customer's data.


Upcoming Events

Automotive Cyber Security, Connectivity & SDV Week 2025

18th - 20th November, 2025

Van der Valk Hotel Berlin Brandenburg, Germany

Automotive Cyber Security, Connectivity & SDV Week 2025

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended