Medibank has released a further update on the recent cyber breach, showing the extent of the possible data stolen and the launch of a comprehensive package for customers affected by the incident.
As the investigation continues, focusing on identifying which systems and networks were accessed and what data was removed, Medibank found that the criminal had access to:
“As previously advised, we have evidence that the criminal has removed some of our customers' personal and health claims data, and it is now likely that the criminal has stolen further personal and health claims data. As a result, we expect that the number of affected customers could grow substantially,” the insurer said in a statement. “Our priority is to continue working to understand the specific data that has been taken for each of our customers so that we can contact them directly to let them know.”
In response to the findings, Medibank will release a support package for affected customers, including:
Medibank has confirmed that its IT systems have not been encrypted by ransomware. However, it has maintained normal business operations, with customers continuing to access health services.
The insurer prioritises preventing further unauthorised entry to its IT network and looks out for any suspicious activity by bolstering existing monitoring, adding further detection and forensics capability across its systems and network, and scaling up analytical support via specialist third parties.
In response to the incident, the Australian Prudential Regulation Authority (APRA) issued some reminders for its regulated entities.