Medibank hackers ignore warning, dump more sensitive data

A migration system that better selects skilled migrants could help solve some of Australiaâs biggest challenges. Photo: AAP
The hackers behind the Medibank data theft have thumbed their noses at the federal government after being warned the âsmartest and toughestâ people in Australia are coming after them.
The ransomware group allegedly behind the hack overnight claimed they had released more sensitive details of customersâ medical records on the dark web.
âAdded one more file Boozy.csv âŚ,â they wrote in a blog update in the early hours of Friday.
The file, which appears to be related to mental health and alcohol issues, comes after a data dump on Thursday named âabortions.csvâ.
âYou telling that is disgusting (woof-woof), that we publish some data,â they wrote on Friday in the blog.
âBut we warned you. we always keep our word, if we wouldnât receive a ransom â we should post this data, because nobody will believe us in the future.â
Medibank branded the latest dump âdisgracefulâ, and urged affected customers to reach out for support if needed.
âThe continued release of this stolen data on the dark web is disgraceful,â Medibank CEO David Koczkar said in a statement on Friday.
âUnfortunately, we expect the criminal to continue to release stolen customer data each day.
âThe relentless nature of this tactic being used by the criminal is designed to cause distress and harm.â
Mr Koczkar said the exploitation was such sensitive information was âdeplorableâ.
âThese are real people behind this data and the misuse of their data is deplorable and may discourage them from seeking medical care,â he said.
âItâs obvious the criminal is enjoying the notoriety. Our single focus is the health and wellbeing and care of our customers.
The ransomware group claimed on Thursday it had demanded $US1 for each of Medibankâs 9.7 million affected customers, for a total of $US9.7 million (almost $15 million).
Home Affairs Minister Clare OâNeil told parliament the government was standing by Medibank customers, who were entitled to have their information kept private after the âmorally reprehensible and criminalâ attack.
âI want the scumbags behind this attack to know that the smartest and toughest people in this country are coming after you,â she said.
Ms OâNeil spoke to Mr Koczkar twice on Thursday to âmake clearâ what was expected of Australiaâs biggest health insurer and to ensure customers were adequately supported.
âI donât want Australians to have to circulate 14 government departments or areas of Medibank in order to get what they deserve and need,â Ms OâNeil said.
âI received the assurance from Medibank ⌠that if a large data dump occurs, they are fully ready to provide services when and if they are needed to Australians who need them.â
The first wave of files dropped on Wednesday included names, birthdates, addresses, email addresses, phone numbers, health claims information, Medicare numbers for Medibankâs ahm customers, and passport numbers for international student clients.
Medibank has confirmed details of almost 500,000 health claims have been stolen, along with personal information, after the group hacked into its system last month.
No credit card or banking details were accessed.
Australian Federal Police investigators are working with international agencies, as well as state and territory police.
Opposition cyber security spokesman James Paterson said anyone who is contacted by a person purporting to have access to their data should immediately report it to authorities.
Senator Paterson has proposed a âsafe harbourâ provision â involving the nationâs cyber security agency, the Australian Signals Directorate, to give companies time in the immediate aftermath of an attack to respond to the crisis without worrying about legal and privacy ramifications.
-with AAP
- Lifeline 131 114
- beyondblue 1300 224 636
Want to see more stories from The New Daily in your Google search results?
- Click here to set The New Daily as a preferred source.
- Tick the box next to "The New Daily". That's it.








