Australia blames Russians for health insurance data theft
A group of “loosely affiliated cybercriminals” operating like a business in
“We believe we know which individuals are responsible, but I will not be naming them,” Kershaw told reporters. “What I will say is that we’ll be holding talks with Russian law enforcement about these individuals."
Prime Minister
“We know where they’re coming from, we know who is responsible, and we say that they should be held to account,” Albanese said.
“The nation where these attacks are coming from should also be held accountable for the disgusting attacks, and the release of information including very private and personal information,” Albanese added.
An official from the
The extortionists have been linked to high-profile Russian cybercrime gang REvil, short for Ransomware Evil and also known as Sodinokibi.
An old REvil dark web site had started redirecting traffic to a new site that hosts the stolen Medibank data.
A Medibank employee’s stolen username and password, which allowed the hackers to enter the company’s database, had been sold on a Russian dark web forum, Hanson said.
Hanson doubted that culprits operating in
But
“There’s potential to conduct operations against the group to disrupt their operations, but in terms of seeing them go to prison or appear before a court, I think that’s pretty unlikely,” Hanson told
Cybercriminals dumped personal medical records on the dark web for a third day on Friday, this time focusing on alcohol-related illnesses, as they pressure Medibank to pay a ransom.
The criminals began dumping customer records Wednesday, including those involving treatments for HIV and drug addiction, which they described as a “naughty” list, after Medibank ruled out paying a ransom for the return of the hacked data.
The focus shifted to terminated pregnancies in Thursday’s dump and on Friday to conditions related to harmful levels of alcohol consumption, in a file the thieves labeled “boozy.” Medical treatment records of more than 700 customers had been published through Friday in what has been described as Australia’s most invasive cybercrime.
Other personal details of many more customers have also been made public that could leave them vulnerable to identity theft or fraud, including phone numbers and email addresses.
Confirming the third dump, Medibank CEO
“The relentless nature of this tactic being used by the criminal is designed to cause distress and harm,” Koczkar said.
“These are real people behind this data and the misuse of their data is deplorable and may discourage them from seeking medical care,” he added.
The gang, which is becoming increasingly better known as BlogXX within cybersecurity circles, blamed
“But we warned you. we always keep our word, if we wouldn't receive a ransom - we should post this data, because nobody will believe us in the future,” they posted on Friday.
Kershaw said Australian government policy did not condone paying ransoms to cybercriminals.
“Any ransom payment, small or large, fuels the cybercrime business model, putting other Australians at risk,” Kershaw said.
Australian authorities are hoping the data remains confined to the dark web and is not spread to a wider audience by social media or reported in detail by the news media.
Albanese urged against anyone accessing the data.
“We need to provide a disincentive for this sort of criminal, disgusting behavior that is reprehensible,” Albanese said.
“It’s causing a great deal of distress in the community. The government acknowledges this and we’re doing all we can to limit the impact of this and to provide that support to people who are going through this distressing time,” Albanese added.


With CAGR of 7.5%, UAE Health Insurance Market to Reach US$ 11.1 Billion by 2027 | IMARC Group
Top Asian News 7:36 a.m. GMT
Advisor News
- Why advisors should offer retirement-longevity planning
- A hybrid approach outperforms the 4% Rule, researchers find
- The missing piece in most retirement plans
- Clients are bringing TikTok insurance advice into advisor meetings
- Embracing a family-centric approach to financial planning
More Advisor NewsAnnuity News
- The Manhattan Life Insurance Company Acquires Union Security Life Insurance Company of New York
- Cayman Islands premier to meet with U.S. reinsurance regulators
- Investigation finds deceptive sales, churning of annuities targeting postal workers
- Corebridge annuity sales slip ahead of Equitable marriage
- California teachers settle class-action lawsuit over in-plan annuity fees
More Annuity NewsHealth/Employee Benefits News
Life Insurance News
- AM Best Affirms Credit Ratings of PT KB Insurance Indonesia
- Westaim Reports Q2 2026 Results for the Quarter Ended June 30, 2026 and Leadership Update for Ceres Life Insurance Company
- Bismarck man convicted of insurance fraud involving dead wife sentenced to prison
- Insurers, rating firms push back on NAIC credit rating oversight plan
- The Manhattan Life Insurance Company Acquires Union Security Life Insurance Company of New York
More Life Insurance News