In October 2022, Medibank Private - Australia's largest private health insurer with 3.9 million customers - was breached by a ransomware affiliate using credentials stolen from a third-party IT contractor. The attackers exfiltrated 9.7 gigabytes of highly sensitive health data including cancer diagnoses, HIV status, mental health treatment records, and claims data for drug and alcohol rehabilitation. When Medibank refused to pay the ransom demand (approximately $10 million AUD), the attackers published the data on a dark web blog linked to LockBit ransomware infrastructure, releasing specific categories designed for maximum harm: a "naughty list" of customers who had sought treatment for drug use, and files identifying customers with HIV diagnoses or cancer treatment.

The Medibank breach was qualitatively different from most corporate data breaches in its deliberate targeting of the most sensitive possible information for publication, and in Medibank's public decision not to pay. The Australian government and cybersecurity community broadly supported the no-payment stance on principle - paying ransoms funds criminal operations and provides no guarantee of data deletion. But the human cost was borne by patients whose most private medical information was weaponized. Several of those patients were subsequently targeted for blackmail. At least one person was reported to have left their job after their employer received their medical information.

Initial Access and Exfiltration

The attacker gained initial access using credentials belonging to a third-party IT contractor who had access to Medibank's systems. The credentials appeared to have been stolen by information-stealing malware (specifically, the credentials were sold via a Russian cybercriminal forum). The attacker used these credentials to log into Medibank's network using its external-facing VPN, which did not require multi-factor authentication.

Once inside, the attacker moved laterally over several weeks, eventually reaching Medibank's data warehouses. The exfiltration occurred in mid-October 2022. Medibank's security monitoring detected unusual activity and the company initially stated, incorrectly, that no customer data had been accessed. The attacker then contacted Medibank directly with proof of the exfiltrated data, at which point Medibank revised its public statements.

The attacker claimed to have downloaded 200 gigabytes of data. Medibank's analysis concluded that 9.7 gigabytes was exfiltrated. The discrepancy was never fully resolved publicly - either the attacker exaggerated the scale to increase leverage, or Medibank's forensics identified that only a subset of what was accessed was actually exfiltrated.

[TECHNICAL NOTE]
The Medibank breach access chain followed what is now a well-documented pattern: credential theft via information stealer malware sold through criminal markets, followed by VPN access using those stolen credentials, followed by lateral movement to high-value data stores. The specific failure that enabled this attack was that Medibank's external VPN access did not require MFA. This is not an obscure hardening technique - it is a baseline control recommended by every major security framework, explicitly required for Australian entities under the Essential Eight (which lists MFA as a top-tier mitigation for external access). The Australian Signals Directorate's Essential Eight framework rates multi-factor authentication for third-party and remote access as Maturity Level 1 - the lowest possible tier, meaning it should be implemented by essentially every organization. The fact that a company storing the medical records of 3.9 million Australians had no MFA on external VPN access as of late 2022 was a compliance failure as much as a technical one. Post-breach analysis by the Australian Prudential Regulation Authority (APRA) - Medibank's regulator - found that Medibank had received prior assessments identifying control gaps that had not been fully remediated before the breach. APRA subsequently took enforcement action against Medibank's parent company under the Prudential Standard CPS 234 (information security).

The Decision Not to Pay

Medibank's decision not to pay was made public and positioned as a principled stance against ransomware economics. The company stated that paying provided no guarantee that the data would be deleted, that payment would fund criminal operations, and that payment might mark Medibank as a willing payer for future attacks. The Australian government publicly supported this position and later moved to implement a legal ban on ransomware payments in certain sectors.

The attacker's response to non-payment was systematic publication of the most sensitive data categories they had identified. The publication strategy was deliberate: rather than dumping all data at once, they published in tranches designed for maximum reputational damage and human harm. A "naughty list" contained claims data for patients who had sought treatment for drug and alcohol abuse. A "good list" distinguished this from a separate file containing records for patients with "interesting" conditions. HIV diagnoses, cancer treatment records, and mental health data were specifically surfaced.

The publication continued over several weeks before the dark web blog went offline. The reasons for it going offline were not publicly confirmed - speculation included law enforcement pressure and disagreements within the criminal operation. By the time it went offline, the core of the sensitive data had been published.

[WARNING]
The Medibank breach crystallized a fundamental ethical tension in ransomware response policy. The "don't pay" advice - standard guidance from law enforcement agencies including the FBI, CISA, and the Australian Cyber Security Centre - is based on sound logic: payment funds criminal operations and creates a perverse incentive to attack targets more likely to pay. But it implicitly requires that the cost of non-payment be borne by victims (in this case, patients whose medical records were published) rather than by organizations that failed to protect the data. When the downstream harm of non-payment is that individual patients have their HIV status or cancer diagnoses published on the dark web, the calculus is harder. Australian Privacy Foundation and health consumer advocates argued that patients should have been notified faster, should have had input into the decision, and that organizations holding highly sensitive health data have an elevated responsibility both to protect it and to consider patient interests when responding to a breach. The no-payment principle remains broadly correct from a macro-economic standpoint - if no one ever paid ransoms, the ransomware industry would collapse. But its application in individual cases with serious human consequences deserves more nuanced discussion than it typically receives.

Attribution and Law Enforcement Response

Australian Federal Police (AFP) attributed the breach to a Russian national and identified him publicly by name in January 2023 - an unusually rapid and specific public attribution. The AFP stated they knew who the attacker was and that they were working with international partners to hold him accountable. The attacker was described as having links to REvil ransomware operations as well as the LockBit affiliate ecosystem. Russian law does not extradite its nationals, meaning criminal prosecution through Australia's courts was not practically available.

The Australian government responded to the breach with several policy actions. The Albanese government announced that it would establish a Standing Operation Dolos - a permanent AFP/ASD cyber task force targeting ransomware groups - and explicitly named and sanctioned the identified attacker. The Australian government also announced it was consulting on legislation to mandate reporting of ransomware payments and, potentially, to prohibit payments in certain categories. Neither the consultation nor the legislation had concluded as of mid-2025.

[IOC]
Medibank breach summary: announced October 13, 2022 by Medibank after attacker contact; initial false statement of no data compromise. Access vector: credentials of third-party IT contractor sold via Russian cybercriminal market (information stealer malware); used to authenticate to Medibank VPN without MFA. Data exfiltrated: 9.7 GB (attacker claimed 200 GB), including 9.7 million customer records with names, dates of birth, Medicare numbers, and for ~480,000 records: health claims data including diagnoses, treating facilities, and procedure codes. Sensitive subsets published: "naughty list" (drug/alcohol treatment claims); HIV diagnoses; cancer treatment records; mental health data. Ransom demand: approximately AUD $10M. Payment: refused. Publication: dark web blog linked to LockBit infrastructure; phased publication over several weeks. Attribution: AFP named Russian national with REvil/LockBit affiliate links, January 2023; sanctioned by Australian government. APRA enforcement: Australian Prudential Regulation Authority launched enforcement action against Medibank's parent company under CPS 234; Medibank agreed to an enforceable undertaking in 2023. Class action: filed by Slater and Gordon on behalf of affected patients; ongoing as of mid-2025. Total regulatory and legal exposure: estimated AUD $700M+ in potential penalties, settlements, and remediation. The breach remains the most damaging health data breach in Australian history.