logo

Scathing report on Medibank cyberattack highlights unenforced MFA

ID: 244d8b0e-bc05-5bb1-aea8-feff79c622bb

STIX ID: report--244d8b0e-bc05-5bb1-aea8-feff79c622bb

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-06-18

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

In October 2022 Medibank was breached after an IT contractor's saved credentials were stolen via information-stealing malware, enabling attackers to access the corporate VPN (which lacked mandatory MFA), move laterally, and exfiltrate 520 GB of customer and health-claims data affecting approximately 9.7 million people; the stolen data was later leaked by a ransomware gang linked to a Russian national and an offshoot of REvil. The OAIC found multiple operational failures, including credential management weaknesses and missed EDR alerts, which prolonged the intrusion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.