Medibank Private Ltd, Australia’s biggest health insurer, said on Thursday hackers had released more of its stolen medical records, as the media reported that the complete set of data on millions of customers was now public.
The Office of the Australian Information Commission (OAIC), the country’s privacy regulator, has also begun investigating how the company handles personal information, Medibank said in a statement.
For the latest headlines, follow our Google News channel online or via the app.
The latest release on the dark web follows progressive uploads, including records of customers’ mental health and alcohol use, that began after Medibank said on November 7 it would not pay a ransom.
“The raw data we have analyzed today so far is incomplete and hard to understand,” chief executive David Koczkar said. “While there are media reports of this being a signal of ‘case closed,’ our work is not over.”
On Thursday, the media reported that a blog, believed by cyber experts to be used by the hackers, carried a new post: “Happy Cyber Security Day!!! Added folder full. Case closed.”
It also included a file that had several compressed files amounting to more than 5 gigabytes.
Reuters has not verified the contents of the latest files uploaded on the dark web, part of the World Wide Web that is accessible only with a special software.
Medibank did not immediately respond to a Reuters question whether it believed all stolen data had now been released.
Australian Federal Police last month said Russia-based hackers were behind the Medibank cyberattack, which compromised the details of almost 10 million current and former customers. Medicare revealed the breach on October 13.
In an update on Thursday morning, Medibank said there were currently no signs that banking data had been stolen. Personal details accessed by hackers were not enough to enable financial fraud, it added.
Six zipped files placed in a folder called “full” and containing raw data believed to have been stolen had been uploaded, Medibank said in a statement.
Australia has been grappling with a recent rise in cyber attacks. At least eight companies, including telecoms company Optus, owned by Singapore Telecommunications, have reported breaches since September.
The OAIC, which is also investigating Optus over the breach, did not immediately respond to a Reuters request for comment on the Medibank investigation.
Technology experts have said Australia has become a target for hackers just as a skills shortage leaves an understaffed, overworked cybersecurity workforce ill-equipped to stop attacks.
Australian police blame Russia-based hackers for attack on Medibank
Australia sees spike in cyberattacks from Iranian, Russian state-linked groups
Ransomware hackers hit Australian defense communications platform
Iran still poses major cybersecurity threat to Gulf: ExpertsIran poses a very real cybersecurity threat to Saudi Arabia and other Gulf countries and could target key industries such as telecoms, oil, and gas, ... Saudi Arabia
US official sees growing ‘aggressive’ cybersecurity threats in AsiaSecretary of Homeland Security Alejandro Mayorkas said the US has observed growing cybersecurity threats both at home and throughout Asia, and is ... Technology
Australian government slams telecoms firm Optus for major cybersecurity breachThe Australian government on Sunday levelled its harshest criticism yet against Optus, the second-biggest telecoms company, for a cybersecurity breach ... World News