In October 2022, Medibank Private - Australia's largest private health insurer with 3.9 million customers - was breached by a ransomware affiliate using credentials stolen from a third-party IT contractor. The attackers exfiltrated 9.7 gigabytes of highly sensitive health data including cancer diagnoses, HIV status, mental health treatment records, and claims data for drug and alcohol rehabilitation. When Medibank refused to pay the ransom demand (approximately $10 million AUD), the attackers published the data on a dark web blog linked to LockBit ransomware infrastructure, releasing specific categories designed for maximum harm: a "naughty list" of customers who had sought treatment for drug use, and files identifying customers with HIV diagnoses or cancer treatment.
The Medibank breach was qualitatively different from most corporate data breaches in its deliberate targeting of the most sensitive possible information for publication, and in Medibank's public decision not to pay. The Australian government and cybersecurity community broadly supported the no-payment stance on principle - paying ransoms funds criminal operations and provides no guarantee of data deletion. But the human cost was borne by patients whose most private medical information was weaponized. Several of those patients were subsequently targeted for blackmail. At least one person was reported to have left their job after their employer received their medical information.
Initial Access and Exfiltration
The attacker gained initial access using credentials belonging to a third-party IT contractor who had access to Medibank's systems. The credentials appeared to have been stolen by information-stealing malware (specifically, the credentials were sold via a Russian cybercriminal forum). The attacker used these credentials to log into Medibank's network using its external-facing VPN, which did not require multi-factor authentication.
Once inside, the attacker moved laterally over several weeks, eventually reaching Medibank's data warehouses. The exfiltration occurred in mid-October 2022. Medibank's security monitoring detected unusual activity and the company initially stated, incorrectly, that no customer data had been accessed. The attacker then contacted Medibank directly with proof of the exfiltrated data, at which point Medibank revised its public statements.
The attacker claimed to have downloaded 200 gigabytes of data. Medibank's analysis concluded that 9.7 gigabytes was exfiltrated. The discrepancy was never fully resolved publicly - either the attacker exaggerated the scale to increase leverage, or Medibank's forensics identified that only a subset of what was accessed was actually exfiltrated.
The Decision Not to Pay
Medibank's decision not to pay was made public and positioned as a principled stance against ransomware economics. The company stated that paying provided no guarantee that the data would be deleted, that payment would fund criminal operations, and that payment might mark Medibank as a willing payer for future attacks. The Australian government publicly supported this position and later moved to implement a legal ban on ransomware payments in certain sectors.
The attacker's response to non-payment was systematic publication of the most sensitive data categories they had identified. The publication strategy was deliberate: rather than dumping all data at once, they published in tranches designed for maximum reputational damage and human harm. A "naughty list" contained claims data for patients who had sought treatment for drug and alcohol abuse. A "good list" distinguished this from a separate file containing records for patients with "interesting" conditions. HIV diagnoses, cancer treatment records, and mental health data were specifically surfaced.
The publication continued over several weeks before the dark web blog went offline. The reasons for it going offline were not publicly confirmed - speculation included law enforcement pressure and disagreements within the criminal operation. By the time it went offline, the core of the sensitive data had been published.
Attribution and Law Enforcement Response
Australian Federal Police (AFP) attributed the breach to a Russian national and identified him publicly by name in January 2023 - an unusually rapid and specific public attribution. The AFP stated they knew who the attacker was and that they were working with international partners to hold him accountable. The attacker was described as having links to REvil ransomware operations as well as the LockBit affiliate ecosystem. Russian law does not extradite its nationals, meaning criminal prosecution through Australia's courts was not practically available.
The Australian government responded to the breach with several policy actions. The Albanese government announced that it would establish a Standing Operation Dolos - a permanent AFP/ASD cyber task force targeting ransomware groups - and explicitly named and sanctioned the identified attacker. The Australian government also announced it was consulting on legislation to mandate reporting of ransomware payments and, potentially, to prohibit payments in certain categories. Neither the consultation nor the legislation had concluded as of mid-2025.