Medibank facing dual court actions over data hack

October 2, 2026 15:17 | News

A hacker moved undetected through Medibank’s network for weeks despite multiple warning flags being raised, a court has been told.

The health insurer is facing both a class action by impacted customers and civil penalties brought by the privacy watchdog over the 2022 hack.

After Medibank declined to pay a ransom, personal data was leaked on the dark web under malicious file names including boozy, STD and psycho.

Federal Court Justice Jonathan Beach heard evidence on Friday to help decide whether the cases will be held jointly or as separate trials.

A lawyer for the class action argued it was in the interests of justice to hear the cases together.

Medibank
Hackers published client data on the dark web after the health insurer refused to pay a ransom fee. (Jono Searle/AAP PHOTOS)

“The technical issues here overlap and intersect at multiple stages … in terms of the architecture of Medibank’s cybersecurity systems (and) the control deficiencies in them,” Wendy Harris KC said.

Outside access was originally gained to Medibank’s network in August 2022, via the personal computer of a third-party contractor.

“What follows is not simply someone entering a network and downloading a database – it’s a progression through the network over a period of weeks,” Ms Harris told the court.

Throughout the breach, several alerts were raised which were not dealt with by Medibank, she said.

“Medibank’s systems, as deficient as they were, were throwing up the canary warnings, but those were effectively ignored,” she said.

police address media
Federal police investigated the hack, in which details of almost 500,000 health claims were leaked. (Lukas Coch/AAP PHOTOS)

“Some weren’t even triaged. Others were reviewed and just closed as false positives or benign activity.”

Once within the system, the hacker gained increasingly higher-level access and moved laterally through Medibank’s network, ultimately extracting 529 gigabytes of customer data.

Data was released under file names including a good list and naughty list, as well as abortions, boozy, psycho, HIV, STD and hepatitis.

“The nature of those publications gives some indication why this proceeding matters to the people whose information Medibank held,” Ms Harris said.

The class action alleges four core failures by Medibank to protect its customers’ data, any of which it says could have prevented the breach had they been in place at the time.

The four failures regarded not having multi-factor authentication in place, as well as failures to document changes to IT assets and lapses in security testing and monitoring.

In response, Neil Young KC called the class action a “total mess”, saying it went well beyond the Office of the Australian Information Commissioner’s case in its allegations of cybersecurity failures.

“Their case has dramatically altered in the last four weeks,” said Mr Young, who is representing Medibank in both matters.

“There are many new allegations of breach.

“In order for us to address those new allegations, that’s going to require time.”

Justice Beach adjourned the matter until October 16, in part to allow the class action party to consolidate its statement of claim.

AAP News

Australian Associated Press is the beating heart of Australian news. AAP is Australia’s only independent national newswire and has been delivering accurate, reliable and fast news content to the media industry, government and corporate sector for 85 years. We keep Australia informed.

Latest stories from our writers

Don't pay so you can read it. Pay so everyone can!

Don't pay so you can read it.
Pay so everyone can!

Pin It on Pinterest

Share This