Medibank hack linked to cybersecurity shortcomings

June 19, 2024
1 min read



TLDR:

  • Medibank suffered a cyberattack in October 2022 compromising data of 9.7 million individuals.
  • The breach was due to cybersecurity failings, including lack of multi-factor authentication.

Major Australian health insurance provider Medibank experienced a cyberattack in October 2022 that compromised the data of 9.7 million individuals. The breach, attributed to now-sanctioned Russian national Alexander Gennadievich Ermakov, was a result of security lapses on Medibank’s part. The breach originated from an IT service desk operator’s home computer that stored Medibank credentials, granting attackers access to the firm’s Microsoft Exchange server and Palo Alto Networks Global Protect VPN. It was found that Medibank had not implemented multi-factor authentication on their VPN, contributing to the breach.

Additionally, the insurer failed to appropriately triage alerts from its endpoint detection and response system in late August, further exacerbating the cybersecurity failings. This breach highlights the importance of robust cybersecurity measures, such as multi-factor authentication, to prevent unauthorized access to sensitive data.


Latest from Blog

Top 20 Linux Admin Tools for 2024

TLDR: Top Linux Admin Tools in 2024 Key points: Linux admin tools streamline system configurations, performance monitoring, and security management. Popular Linux admin tools include Webmin, Puppet, Zabbix, Nagios, and Ansible. Summary

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives