Hacker releases Australian health insurer’s customer data

Advertisement

Advertise with us

CANBERRA, Australia (AP) — Client data from Medibank, Australia's largest health insurer, was released by an extortionist on Wednesday, including details of HIV diagnoses and drug abuse treatments, after the company refused to pay a ransom for the personal records of almost 10 million current and former customers.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 08/11/2022 (1396 days ago), so information in it may no longer be current.

CANBERRA, Australia (AP) — Client data from Medibank, Australia’s largest health insurer, was released by an extortionist on Wednesday, including details of HIV diagnoses and drug abuse treatments, after the company refused to pay a ransom for the personal records of almost 10 million current and former customers.

The material released on the dark web appeared to be a sample of the data that Medibank has determined was stolen last month, the company said. Medibank expects the thief will continue releasing data.

“This is a criminal act designed to harm our customers and cause distress,” Medibank CEO David Koczkar said in a statement that reiterated a previous apology to customers.

A computer and phone display pages from the Medibank Private website in Sydney, Tuesday, Nov. 8, 2022. Medibank client data was published by an extortionist Wednesday, Nov. 9, including details of individuals' medical procedures, after Australia’s largest health insurer refused to pay a ransom for the personal records of almost 10 million current and former customers. (AP Photo/Rick Rycroft)
A computer and phone display pages from the Medibank Private website in Sydney, Tuesday, Nov. 8, 2022. Medibank client data was published by an extortionist Wednesday, Nov. 9, including details of individuals' medical procedures, after Australia’s largest health insurer refused to pay a ransom for the personal records of almost 10 million current and former customers. (AP Photo/Rick Rycroft)

“We take seriously our responsibility to safeguard our customers and we stand ready to support them,” he added.

The data included what the thief called a “naughty list” of more than 100 names. Among them were patients who had contracted HIV and others who were treated for addictions to drugs and alcohol and for mental health problems.

One of the exposed customers contacted by Nine News television responded with anger toward Medibank.

“Letting customers discover their most sensitive information imaginable has been published and hearing it on the news, Medibank’s response has been pathetic,” the unidentified man, whose image was not broadcast, told Nine.

Cybersecurity Minister Clare O’Neil, who is a Medibank customer and has had personal data stolen, urged social and traditional media companies to prevent their platforms from being used to share people’s stolen medical histories.

“If you do so, you will be aiding and abetting the scumbags who are at the heart of these criminal acts and I know that you would not do that to your own country and your own citizens,” O’Neil told Parliament.

She said the number of people whose medical information has been released was “small at this stage.”

“But I want the Australian people to understand that that is likely to change, and we are going through a difficult period now that may last for weeks, possibly months, not days and hours,” O’Neil added.

Prime Minister Anthony Albanese, who is also a Medibank customer, welcomed the company’s refusal to pay the hacker to have the records returned.

“This is really tough for people. I’m a Medibank Private customer as well and it will be of concern that some of this information has been put out there,” Albanese told reporters, referring to a Medibank brand.

“The company has followed the guidelines effectively, the advice, which is to not engage in a ransom payment. If you go down this road, then you end up with more difficulties potentially across a wider range,” Albanese said.

The thieves had reportedly threatened to expose the diagnoses and treatments of high-profile customers unless a ransom of an undisclosed amount was paid, but Medibank decided there was “only a limited chance” that a payment would prevent the data from being published.

A blogger using the name “Extortion Gang” posted Monday night on the dark web that “data will be publish in 24 hours.”

Medibank this week updated its estimate of the number of people whose personal information was stolen from 4 million two weeks ago to 9.7 million. The stolen data includes health claims of almost 500,000 people including diagnoses and treatments, the company said.

The theft of the personal records of 9.8 million customers of Optus, Australia’s second-largest wireless telecommunications carrier, that was discovered on Sept. 21 prompted the government to promise heftier penalties for corporations that fail to protect private data.

The House of Representatives on Wednesday passed an urgent bill that would increase penalties for serious breaches of the Privacy Act from 2.2 million Australian dollars ($1.4 million) to AU$50 million ($32 million) or more.

The government hopes the bill will be passed by the Senate and become law this month.

Report Error Submit a Tip

More Stories

Police in standoff in Westwood

1 minute read Updated: Yesterday at 4:43 PM CDT

Winnipeg police officers are in a standoff that began Thursday morning in Westwood.

Police were called to Byrd Avenue shortly before 9:30 a.m. after a man was seen walking with what appeared to be a firearm, said Winnipeg Police Service spokesman Const. Claude Chancy.

Officers have identified a home connected to the investigation, he said. Police have taken one man into custody and seized several weapons, including a firearm, said Chancy. He was not sure if the man arrested was the individual spotted walking with the firearm.

A section of Byrd Avenue and Davis Crescent has been closed to traffic.

MPI restricts loan program to winter tires only

Nicole Buffie 5 minute read Preview

MPI restricts loan program to winter tires only

Nicole Buffie 5 minute read Yesterday at 6:54 PM CDT

Manitoba Public Insurance is getting strict about its winter tire program after years in which customers used it to buy other types of tires.

As of Oct. 1, only tires that are “designed and marketed solely for winter driving conditions, including snow and ice,” will be eligible for financing through the public insurer.

Currently, all-weather, all-season, four-season and year-round tires are included in the program, which allows MPI clients to pay the cost in monthly installments. The program, established in 2014, offers financing for up to $2,000, plus interest.

In an email to retailers, MPI says the program is being changed so it “helps ensure customers receive the full winter-driving safety benefits associated with dedicated winter tires.”

Read
Yesterday at 6:54 PM CDT

Former Gilbert Plains CAO forged doc’s note to get out of court: RCMP

Erik Pindera 4 minute read Preview

Former Gilbert Plains CAO forged doc’s note to get out of court: RCMP

Erik Pindera 4 minute read Updated: 12:12 PM CDT

A former rural municipal official awaiting sentencing for stealing more than $500,000 from community coffers has been accused of forging a fake doctor’s note to get out of attending court.

Amber Fisher, the former chief administrative officer for the Rural Municipality of Gilbert Plains, pleaded guilty to one count of theft over $5,000 last year.

Dauphin RCMP say investigators learned Fisher, 42, had submitted the note indicating she would be unable to attend court for her Sept. 2 sentencing, after she was seriously injured in a vehicle collision on July 22.

Fisher’s lawyer submitted the note to the court and the judge adjourned her sentencing to a later date.

Read
Updated: 12:12 PM CDT

Steinem’s life a lesson in audacity, generosity, courage

Jen Zoratti 5 minute read Preview

Steinem’s life a lesson in audacity, generosity, courage

Jen Zoratti 5 minute read 11:58 AM CDT

I wish I could tell you the first time I heard the word “feminist,” it was from Gloria Steinem, but it was definitely from a Spice Girl.

Props, though, to the Spice Girls for actually using the F word. So many people these days are afraid of it — afraid of using it, afraid of identifying with it, afraid of claiming it for themselves.

Gloria Steinem wasn’t, and she made it so we wouldn’t be either.

The trailblazing American journalist and feminist activist died this week. She was 92. She was a lion, a woman who fought for rights and freedoms that many subsequent generations take for granted — and which, in the last decade especially, have been increasingly threatened.

Read
11:58 AM CDT

Manitoba selects consulting firm Nueconomy as India trade rep

Gabrielle Piché 3 minute read 6:00 AM CDT

The Manitoba government has hired an India-based consulting firm to act as its new trade representative in the South Asia nation.

It will announce its choice of strategic consulting firm Nueconomy today.

The company — with offices in Delhi, Mumbai and Bangalore — has already begun working with the province. One of its directors attended Fi India, a food ingredients event, last week to promote Manitoba crops such as pulses, according to a company LinkedIn post.

Representatives from Nueconomy weren’t available for comment by print deadline Thursday.

‘Where are they going to go?’: encampment policy blamed for homeless people sleeping outside thrift store

Scott Billeck 5 minute read Preview

‘Where are they going to go?’: encampment policy blamed for homeless people sleeping outside thrift store

Scott Billeck 5 minute read Wednesday, Sep. 2, 2026

The owner of a Portage Avenue thrift shop says the city’s encampment ban has pushed dozens of homeless people from tent communities to spaces near her store.

Susan Lockhart, who runs Just Like New to You at 635 Portage Ave., says anywhere from 25 to 50 people can be found at any given time behind the store and along the back lane stretching between Sherbrook and Furby streets.

“Where are they going to go?” she said Wednesday from her shop. “I was just here on the weekend and I couldn’t get to our back door. There were people everywhere. Mattresses.”

Earlier this week, the city reported 275 people were known to be living in 72 encampments across Winnipeg — down from 100 encampments housing about 700 people last September. The report also noted that 141 sites have been remediated since the city’s encampment policy came into effect in November.

Read
Wednesday, Sep. 2, 2026