In October 2022 the Australian health insurer Medibank disclosed a breach affecting the personal and medical data of 9.7 million current and former customers. The attackers demanded around $10 million. Medibank refused.
Publication followed in stages on a criminal forum. Reported categories include names, dates of birth, passport numbers and medical claims data. On 10 November 2022 a file labelled "abortions" was posted, reported to concern claimed procedures including terminations, miscarriages and ectopic pregnancies. Other releases were reported to concern alcohol-related illness.
The Selection Is The Attack
A ransomware operation that publishes a customer database is applying pressure through volume. Sorting the medical records by procedure and releasing the most stigmatised category first is applying it through the specific harm to specific people.
This corpus argues repeatedly that the standard remedies are poorly matched to the harm — credit monitoring at 25-1031, identity replacement at 26-0726. Here they are not merely poorly matched; they are unrelated. No monitoring service, no settlement fund and no credit freeze addresses a person’s termination being published under their name. There is no remedy in the catalogue for this, and the file exists partly to record that.
Refusal Was Still Right, And It Still Cost
The desk does not treat non-payment as costless. Paying buys a promise from a party whose business model is breaking promises, and this corpus has recorded enough re-extortion to regard the purchase as unreliable. Refusal was defensible.
It was also paid for by people who were not asked. The company made a decision about corporate policy and 9.7 million customers absorbed the consequence, in a currency — a published medical history — that the company itself did not spend. The corpus files the same structure at 22-0508, where a state refused and its importers waited at the border.
Former Customers
The affected population included former customers. Someone who left Medibank years earlier had no live relationship, no account to close and no ability to have influenced any of it, and their claims history was still there to be sorted.
The corpus records retention as a category of exposure in its own right at 22-0922 and 26-0730. Data kept past the relationship that justified it is a liability held on behalf of people who cannot act on it.
Built on contemporaneous reporting of the breach and the subsequent publications. The 9.7 million figure, the ~$10m demand, Medibank’s refusal, the staged publication on a criminal forum, the reported categories, and the 10 November 2022 posting of a file labelled "abortions" concerning claimed procedures are as reported at the time. This desk has not accessed the published data and will not; the characterisation of its contents is taken from reporting. No individual is identified or identifiable from anything in this file. Subsequent sanctions and litigation relating to the incident are outside its scope. Graded high. Corrections: corrections@forensicpost.com.