HomeSecurityMedibank: Refuses to pay ransom - Hackers pressure with data leak

Medibank: Refuses to pay ransom – Hackers pressure with data leak

Medibank hack: Last month's ransomware attack on Australian health insurance provider Medibank Private Limited was allegedly carried out by a gang many believe to be associated with the well-known REvil while others track it as BlogXX .

Medibank is one of Australia's leading and largest private health insurance providers, with over 3.9 million members and 4,000 employees. It seems to be the choice of many customers because it offers a wide range of plans, competitive prices and excellent customer service.

Medibank ransomware

While the attack on Medibank had not been attributed to a ransomware group until now, the company confirmed that what it observed matched typical ransomware activity.

See also: Microsoft sued for piracy of open source software via GitHub Copilot

The ransomware gang that claimed responsibility for the attack added a new entry to its data leak site yesterday, threatening to leak data allegedly stolen from Medibank's systems within 24 hours.

The group has not said how much data it stole from Medibank's network and has not provided hard evidence to support its claims.

Resurgence of REvil ransomware?

In October 2021, the REvil ransomware gang was shut down after law enforcement breached its Tor servers. Russia then reportedly arrested some of the members involved with the group.

However, in April 2022, Tor websites for the operation began redirecting visitors to new websites for an operation called “BlogXX .” In private conversations with victims, the threat actors referred to themselves as Sodinokibi – a name that had originally been used by the REvil operation .

Additionally, security researchers have verified that the new feature's encryptor was based on the original REvil source code.

The above makes some believe that we are talking about a revival of REvil ransomware, either by its developers or other members.

However, according to MalwareHunterTeam, this group is actually BlogXX, a new venture with connections to REvil.

Medibank: Refuses to pay ransom - Hackers pressure with data leak
Medibank hack: Company refuses to pay ransom – Ransomware gang presses ahead with data leak

Medibank does not want to pay the ransom

Although Medibank has not confirmed which ransomware group is behind the attack, the company said in a new press release that it has refused to pay the ransom demanded by the attackers.

See also: RomCom RAT operators exploit well-known software to distribute malware

Based on the extensive advice we have received from cybercrime experts, we believe there is only a limited chance that paying the ransom will secure the return of our customers’ data and prevent its publication,” the company said.

Additionally, Medibank noted that if it chooses to pay the ransomware gang, this will likely serve as an incentive for future attacks against other customers whose data has been compromised.

Paying the ransom will not only encourage others to attack Australian organizations, putting more people at risk, but it will also line the pockets of criminals.

"Paying the ransom puts more people at risk, making Australia a bigger target," the company said, adding that its decision aligns with what the Australian government believes.

Medibank: Refuses to pay ransom - Hackers pressure with data leak

Medibank hack: Attackers had access to millions of customers' data

The insurance company initially said hackers it had indeed accessed some of had found no evidence that customer data was accessed or stolen during the ransomware attack, but later admitted that its customer data.

Now, with the threat of data leaks more acute than ever, Medibank has revealed that hackers who breached its systems gained access to sensitive information belonging to millions of customers.

See also: Robin Banks phishing service is back up and running

The data that Medibank believes was exposed during the ransomware attack and subsequent breach includes:

  • The personal information of 9.7 million current and former customers and authorized representatives, including names, dates of birth, addresses, phone numbers and email addresses
  • Medicare numbers for AHM health insurance customers (but not expiration dates)
  • Passport numbers (not expiration date) and visa details for some customers. 
  • Health data for almost half a million Medibank, ahm and other customers
  • All information about the healthcare provider, such as names, numbers, and addresses.

Medibank also said that the ransomware gang behind the October attack did not have access to sensitive financial information (such as credit card and bank transaction details ), primary identity documents (e.g. driving licenses) or health claim data for additional services (such as dental, physiotherapy, optical and psychological).

Medibank warned: "Customers should remain vigilant as criminals may post data online or attempt to contact customers directly."

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS