---
title: "Insurance Company Refuses to Pay Ransom, So Hackers Start Releasing Health Records of Up To 10 Million People"
description: "Unidentified hackers have stolen the health records of millions of customers of Australian health insurer Medibank, releasing them on the dark web."
date: "2022-11-13"
modified: "2022-11-13"
authors:
  - name: "Frank Landymore"
    job_title: "Contributing Writer"
    link: "https://futurism.com/authors/flandymore"
url: "https://futurism.com/the-byte/insurance-company-hackers-health-records"
categories:
  - "Future Society"
tags:
  - "cybersecurity"
  - "data breach"
  - "hackers"
  - "the digest"
---

# Insurance Company Refuses to Pay Ransom, So Hackers Start Releasing Health Records of Up To 10 Million People

![Unidentified hackers have stolen the health records of millions of customers of Australian health insurer Medibank, releasing them on the dark web.](<https://futurism.com/wp-content/uploads/2022/11/insurance-company-hackers-health-records.jpg>)
*\<em\>Image: Getty Images\</em\>*

## Breaching Whales

Hackers plundered the health records of millions of customers from Australian health insurance provider Medibank, then dumped them on the dark web after Medibank refused to pay the demanded ransom.

The hack first came to light in October, when it was unclear how much the hackers demanded in ransom money or how much data had been compromised. Regardless, Medibank didn't play ball, and true to their word, the hackers uploaded a batch of data.

According to Medibank, outside of health information the data also includes "personal data such as names, addresses, dates of birth, phone numbers, email addresses, Medicare numbers for ahm customers (not expiry dates), in some cases passport numbers for our international students (not expiry dates), and some health claims data," the company stated in a [tweet](<https://twitter.com/medibank/status/1590164893998936064>).

The private healthcare provider believes that all the data of its 3.9 million customers has been compromised. That number could be as high as nearly 10 million, if former customers are included, though the total extent of the breach remains unclear.

And what's worse is that Medibank believes that the hackers will only [continue to post more stolen data](<https://www.reuters.com/technology/australias-medibank-says-hacker-leaks-customer-data-2022-11-08/>).

## Hidden Identity

Disturbingly, the hackers have posted "naughty" and "nice" lists of the stolen health records, [*Gizmodo* reports](<https://gizmodo.com/hackers-health-info-online-medibank-pay-onion-dark-web-1849760742>). The "naughty" list is especially invasive, since it picks people based on sensitive health histories like seeking treatment for addiction and eating disorders.

So far, the hackers have refused to identify themselves, not even adopting a collective moniker (assuming they are, in fact, more than one person). As of now, the only clue as to who they are is the fact that the website of the now-defunct Russian ransomware operation REvil, redirects to the hackers' blog, [according to *BleepingComputer*](<https://www.bleepingcomputer.com/news/security/ransomware-gang-threatens-to-release-stolen-medibank-data/>).

"P.S. I recommend to sell medibank stocks," the hackers wrote in broken English, [screenshotted here](<https://twitter.com/Cyberknow20/status/1589995449494441987?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1589995449494441987%7Ctwgr%5E9d9eaf43565da64811bd704db9e46131d5c560bf%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fwww.vice.com%2Fen%2Farticle%2Fepz844%2Fhackers-are-posting-australian-health-insurance-data-on-the-dark-web>).

In addition, they claim the ransom they demanded was $10 million.

## The Buck Stops

All the while, many have understandably expressed outrage at Medibank's handling of the situation. At best, the health insurer's response could be described as sluggish. Others [would argue criminal](<https://www.abc.net.au/news/2022-11-08/medibank-data-leak-threatened/101627856>).

Inexplicably, Medibank [didn't even have cyberinsurance](<https://www.arnnet.com.au/article/702737/no-cyber-insurance-medibank-breach-hits-four-million-customers/>), meaning it might have to shell out up to $22 million in damages, excluding legal fees.

Medibank initially assured customers that, while there had been a breach, no data was compromised. The company's leaders couldn't have imagined how wrong they'd turn out to be.

**More on data breaches:** *[Parent-Teacher Messaging App Hacked to Send Mom and Dad Horrifying Images](<https://futurism.com/the-byte/parent-teacher-messaging-app-hacked>)*

## Author
At Futurism, my work has often centered on bringing a sense of clarity and insight to complex topics ranging from the regulation of emerging technologies to the esoteric ideologies of Silicon Valley executives, while striving not to lose the poetic sense of awe inspired by often-obscure fields like astrophysics and quantum computing. I broke the story of CNET using AI to produce articles that turned out to be riddled with factual errors and plagiarism — a dam-breaking inflection point, as I've reported, that's inspired copycats and endless discourse while beguiling stakeholders ranging from tech giants to purveyors of spam around the web. My work at Futurism has been cited by publications including CBS News, the Los Angeles Times, Vice, Gizmodo, Engadget, the Verge, and Vanity Fair. I grew up in locales ranging from India to China, and now live in the exotic suburbs of Virginia. In my free time, I'm an avid reader of weird sci-fi literature, an aficionado of East Asian cinema, and, regrettably, a relapsed gamer. Allegedly, I’m working on a debut novel, currently untitled.

### Author social links  
[Bluesky](<https://bsky.app/profile/f-w-l.bsky.social>)