Medibank bleeds $26 million in cyber costs following hack
The company believes this figure could rise to $45 million for the 2023 financial year


Medibank has revealed that it has suffered $26.2 million AUD (£14.7 million) in cyber crime-related costs following the hack of its systems in the second half of 2022.
It expects its cyber crime costs to be around $40-$45 million for the 2023 financial year. This involves additional investments in IT security, but excludes further customer and other remediation, regulatory, or litigation-related costs.
According to IBM's figures in 2022, the average cost to an Australian organisation following a ransomware attack was $4.5 million, putting Medibank's losses considerably above the average.
The attacker accessed its systems through a stolen username and password belonging to a third-party IT service provider, Medibank revealed. This was used to access the company’s network through a misconfigured firewall which lacked an additional digital security certificate.
The company said the attacker then went on to obtain more usernames and passwords to access other systems. Since the company was alerted to the attack on 11 October, it confirmed that it hasn’t detected any additional criminal activity on its systems since 12 October.
“We recognise the significant impact the cyber crime event has had on our customers. We will continue to support them through our Cyber Response Support Program, which includes mental health and wellbeing support, identity protection, and financial hardship measures,” said David Koczkar, CEO at Medibank.
RELATED RESOURCE
A roadmap to Zero Trust with Cloudflare and CrowdStrike
Achieve end-to-end protection across endpoints, networks, and applications
“There is more work to do, and the lessons we have learnt from the cyber crime will continue to shape our response and we will emerge stronger.”
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Since the attack, the company said it has implemented greater security controls, including ensuring its firewall authentication is fully configured across its entire network.
It has also improved its network monitoring and added further detection and forensics capabilities to help defend against the 18 million perimeter attacks it experiences every day.
An unknown hacker targeted Medibank in October 2022 and threatened to release stolen data unless the company paid a ransom.
Data belonging to 9.7 million former and current customers was exposed, which was believed to include information like health claims data and passport numbers. At the time, the company thought the hack could set it back by $25-$35 million, especially since it didn’t have cyber insurance.
Medibank delivered its most detailed account of the 2022 attack in its half-year earings report released on Thursday.
It reported a gross profit of $233.3 million, an increase of 5.9% compared to the previous half-year. Over the past year, the company has gained around 35,000 customers, despite losing 13,000 clients following the attack in the second half of 2022.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Capita handed £50m London police contract weeks after losing pension data
News The outsourcer will provide digital fraud reporting services after its cyber incident disclosure drew criticism
By Rory Bathgate Published
-
Supercharge trust for operations
Whitepaper Innovating through uncertainty
By ITPro Last updated
-
Western Digital suffers cyber attack, shuts down systems
News Customers are taking to Twitter to report they’re unable to log into their storage products through Western Digital’s online portal
By Zach Marzouk Published
-
Lazarus blamed for 3CX attack as byte-to-byte code match discovered
News Additional analysis suggested 3CX developer teams ignored "red flags"
By Zach Marzouk Published
-
Latitude Financial's data policies questioned after more than 14 million records stolen
News Some of the data is from at least 2005 and includes customers’ name, address, and date of birth
By Zach Marzouk Published
-
Some GitHub users must take action after RSA SSH host key exposed
News One cloud security expert likened the incident to the infamous HeartBleed bug from 2014
By Zach Marzouk Published
-
Latitude hack now under state investigation as customers struggle to protect their accounts
News The cyber attack has affected around 330,000 customers, although the company has said this is likely to increase
By Zach Marzouk Published
-
IDCARE: Meet the cyber security charity shaping Australia and New Zealand's data breach response
Case Studies IDCARE is recruiting a reserve army to turbocharge the fightback against cyber crime not just in the region, but in the interests of victims all over the world
By Zach Marzouk Published