TLDR:
- Medibank suffered a cyberattack in October 2022 compromising data of 9.7 million individuals.
- The breach was due to cybersecurity failings, including lack of multi-factor authentication.
Major Australian health insurance provider Medibank experienced a cyberattack in October 2022 that compromised the data of 9.7 million individuals. The breach, attributed to now-sanctioned Russian national Alexander Gennadievich Ermakov, was a result of security lapses on Medibank’s part. The breach originated from an IT service desk operator’s home computer that stored Medibank credentials, granting attackers access to the firm’s Microsoft Exchange server and Palo Alto Networks Global Protect VPN. It was found that Medibank had not implemented multi-factor authentication on their VPN, contributing to the breach.
Additionally, the insurer failed to appropriately triage alerts from its endpoint detection and response system in late August, further exacerbating the cybersecurity failings. This breach highlights the importance of robust cybersecurity measures, such as multi-factor authentication, to prevent unauthorized access to sensitive data.