Australian government blames Russian hackers for cyber attack against Medibank, a major Australian healthcare company and breached the data of 9.7 million people, including the country’s prime minister, police said Friday.
Australian government blames the Russian hackers started leaking the data earlier this week after Medibank — the country’s largest health insurer — refused to pay a $9.7 million (Aus$15 million) ransom.
Australian Federal Police commissioner Reece Kershaw blamed the attack on Russia-based “cyber criminals”.
“We believe those responsible for the breach are in Russia,” he told reporters.
if States "legalize" antiabortion private right of action $$ suits, #HIPAA should make illegally obtained data inadmissible poisoned evidence for them (but not yet) cc. @heyprofbow @notmuchelse @Hegemommy
Australia: Russian hackers attack on Medibank https://t.co/8BCNralJVL
— Hfelld (@noFelld) November 11, 2022
“Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches across the world.”
The hackers have been drip-feeding the stolen data to a dark web forum.
The first leaks appeared to have been selected to cause maximum harm: targeting those who received treatment related to drug abuse, sexually transmitted infections, or pregnancy terminations.
Kershaw said it was a crime that could impact “millions of Australians”.
“These cyber criminals are operating like a business with affiliates and associates who are supporting the business.”
He added that Australian police would be working with Interpol and seeking the cooperation of their counterparts in Russia.
“We’ll be holding talks with Russian law enforcement about these individuals,” he said.
“Russia benefits from the intelligence sharing and data shared through Interpol and with that comes responsibilities and accountability.”
Kershaw said police knew the identities of the hackers but he would not be naming them.
The hackers who stole the personal data of customers of Australia’s largest health insurer Medibank have released a data file containing medical documents related to abortion.https://t.co/LFPQB7E3g5
— WION (@WIONews) November 11, 2022
Cybersecurity analysts have suggested they could be linked to Russian hacker group REvil.
REvil — an amalgam of ransomware and evil — was reportedly dismantled by Russian authorities earlier this year, after extracting an $11 million ransom from JBS Foods, a major food conglomerate.
Cover their tracks
Australian National University cyber security expert Thomas Haines said tracking the hackers down was the easiest part for police.
“It’s unusual for hackers to cover their tracks so well that you don’t know where they came from,” he told AFP.
“But there are certain areas of the world where the ability to apply any pressure is effectively zero.”
Kershaw said Australian police were taking “covert measures” to bring the hackers to justice.
“To the criminals, you know we know who you are,” he said.
Read more: Chinese hackers break security barriers to access US defense
“The Australian Federal Police has some significant runs on the scoreboard when it comes to bringing overseas offenders back to Australia to face the justice system.”
Home Affairs Minister Clare O’Neil on Thursday said the “smartest and toughest” people in Australia were hunting down the hackers.
In a taunting reply posted to the dark web early Friday morning, the hackers said: “We always keep our word.”
“We should post this data, because nobody will believe us in the future.”
AFP story with additional input by Global Village Space news desk.