AP

Australian health insurer says data of all customers hacked

Oct 25, 2022, 7:40 PM | Updated: Oct 26, 2022, 2:56 pm

People walk past a Medibank branch in Sydney, Wednesday, Oct. 26, 2022. Medibank, Australia's large...

People walk past a Medibank branch in Sydney, Wednesday, Oct. 26, 2022. Medibank, Australia's largest health insurer, said a cybercriminal had hacked the personal data of all its 4 million customers as the government introduced legislation that would increase penalties for companies that fail to protect clients' private information. (AP Photo/Rick Rycroft)

(AP Photo/Rick Rycroft)

CANBERRA, Australia (AP) — Australia’s largest health insurer said on Wednesday a cybercriminal had hacked the personal data of all its 4 million customers, as the government introduced legislation that would increase penalties for companies that fail to protect clients’ private information.

Medibank said “significant amounts of health claims data” had also been accessed in the breach, which was reported to police a week ago when trade in the company’s shares was halted.

The thief has demanded ransom and has reportedly threatened to expose the diagnoses and treatments of high-profile customers.

Medibank said its priority was to discover the specific data stolen in relation to each customer and to share that information with those customers.

The company had previously said the breach was thought to be limited to its subsidiary AHM and foreign students.

“Our investigation has now established that this criminal has accessed all our private health insurance customers’ personal data and significant amounts of their health claims data,” Medibank chief executive David Koczkar said in a statement to the Australian Securities Exchange.

“This is a terrible crime – this is a crime designed to cause maximum harm to the most vulnerable members of our community,” Koczkar added, with an apology to customers.

The government has been planning urgent legislative reforms on cybersecurity regulation since a hacker stole the personal data of almost 10 million current and former customers of Optus, Australia’s second-largest wireless telecommunications carrier.

Optus became aware on Sept. 21 that personal data of more than one-third of Australia’s population of 26 million had been stolen.

In introducing amendments to the Privacy Act to Parliament on Wednesday, Attorney-General Mark Dreyfus mentioned both companies and MyDeal, an online retail intermediary that lost the data of 2.2 million customers in a hack revealed two weeks ago.

“As the Optus, Medibank and MyDeal cyberattacks have recently highlighted, data breaches have the potential to cause serious financial and emotional harm to Australians, and this is unacceptable,” Dreyfus told Parliament.

“Governments, businesses and other organizations have an obligation to protect Australians’ personal data, not to treat it as a commercial asset,” Dreyfus added.

The government is critical of companies that amass more customer data than necessary to make money from it in ways unrelated to the services for which the information was provided.

The penalties for serious breaches of the Privacy Act would increase from 2.2 million Australian dollars ($1.4 million) now to AU$50 million ($32 million) under the proposed amendments.

A company could also be fined the value of 30% of its revenues over a defined period if that amount exceeded AU$50 million ($32 million).

Medibank said on Wednesday it did not have cyber insurance and estimated the hack would reduce its earnings by between AU$25 million ($16 million) and AU$35 million ($22 million) by early next year.

The Medicare trading halt was lifted on Wednesday and shares slid more than 14% in early trading.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.


              A man walks past a Medibank branch in Sydney, Wednesday, Oct. 26, 2022. Medibank, Australia's largest health insurer, said a cybercriminal had hacked the personal data of all its 4 million customers as the government introduced legislation that would increase penalties for companies that fail to protect clients' private information. (AP Photo/Rick Rycroft)
            
              People walk past a Medibank branch in Sydney, Wednesday, Oct. 26, 2022. Medibank, Australia's largest health insurer, said a cybercriminal had hacked the personal data of all its 4 million customers as the government introduced legislation that would increase penalties for companies that fail to protect clients' private information. (AP Photo/Rick Rycroft)

AP

Lead water pipes pulled from underneath the street are seen in Newark, N.J., Oct. 21, 2021. (AP Pho...

Associated Press

Biden to require cities to replace harmful lead pipes within 10 years

The Biden administration has previously said it wants all of the nation's roughly 9 million lead pipes to be removed, and rapidly.

4 days ago

Facebook's Meta logo sign is seen at the company headquarters in Menlo Park, Calif., on, Oct. 28, 2...

Associated Press

Meta shuts down thousands of fake Facebook accounts that were primed to polarize voters ahead of 2024

Meta said it removed 4789 Facebook accounts in China that targeted the United States before next year’s election.

4 days ago

A demonstrator in Tel Aviv holds a sign calling for a cease-fire in the Hamas-Israel war on Nov. 21...

Associated Press

Hamas releases a third group of hostages as part of truce, and says it will seek to extend the deal

The fragile cease-fire between Israel and Hamas was back on track Sunday as the first American was released under a four-day truce.

8 days ago

Men look over the site of a deadly explosion at Al-Ahli Hospital in Gaza City, Wednesday, Oct. 18, ...

Associated Press

New AP analysis of last month’s deadly Gaza hospital explosion rules out widely cited video

The Associated Press is publishing an updated visual analysis of the deadly Oct. 17 explosion at Gaza's Al-Ahli Hospital.

12 days ago

Peggy Simpson holds a photograph of law enforcement carrying Lee Harvey Oswald's gun through a hall...

Associated Press

JFK assassination remembered 60 years later by surviving witnesses to history, including AP reporter

Peggy Simpson is among the last surviving witnesses who are sharing their stories as the nation marks the 60th anniversary.

12 days ago

Israeli Prime Minister Benjamin Netanyahu, chairs the weekly cabinet meeting in Jerusalem, Sunday, ...

Associated Press

Israeli Cabinet approves cease-fire with Hamas; deal includes release of 50 hostages

Israel’s Cabinet on Wednesday approved a cease-fire deal with the Hamas militant group that would bring a temporary halt to a devastating war.

13 days ago

Sponsored Articles

...

Desert Institute for Spine Care

Desert Institute for Spine Care (DISC) wants to help Valley residents address back, neck issues through awake spine surgery

As the weather begins to change, those with back issues can no longer rely on the dry heat to aid their backs. That's where DISC comes in.

...

Midwestern University

Midwestern University: innovating Arizona health care education

Midwestern University’s Glendale Campus near Loop 101 and 59th Avenue is an established leader in health care education and one of Arizona’s largest and most valuable health care resources.

...

DAY & NIGHT AIR CONDITIONING, HEATING AND PLUMBING

Importance of AC maintenance after Arizona’s excruciating heat wave

An air conditioning unit in Phoenix is vital to living a comfortable life inside, away from triple-digit heat.

Australian health insurer says data of all customers hacked