logo

US, UK, Australia sanction REvil hacker behind Medibank data breach

ID: e86d5152-1c30-5516-ac17-3ee6284c149e

STIX ID: report--e86d5152-1c30-5516-ac17-3ee6284c149e

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-01-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report outlines the 2022 Medibank ransomware incident attributed to Aleksandr Gennadievich Ermakov (linked to REvil/BlogXXX), in which attackers accessed and leaked sensitive personal and health data for approximately 10 million customers; Australia, the US, and the UK have publicly attributed the attack, published aliases and images, and imposed coordinated sanctions to disrupt the actor's ability to operate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.