Medibank said attackers accessed personal data belonging to all of its customers and some authorized representatives, affecting about 9.7 million current and former customers. The Australian health insurer said the compromised information included identifying details and health claims data for roughly 480,000 customers, and warned that all accessed data may have been stolen. Medibank later said it would not pay the ransom, citing expert advice that payment would not ensure the return of data or prevent its publication, while Australian officials backed the decision and warned that ransom payments fuel further extortion.
In Romania, hospitals were forced offline after a ransomware attack hit a healthcare IT platform used by multiple medical facilities, disrupting operations across the country. Reporting indicated the crisis was linked to a third-party incident, underscoring how attacks on shared service providers can cascade across healthcare organizations. Together, the incidents highlight how cybercriminals are targeting healthcare entities through both direct intrusions and attacks on critical external platforms, exposing sensitive patient data and interrupting care delivery.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Reporting the following day clarified that the Romanian healthcare disruption was tied to a ransomware incident at a third-party IT provider rather than separate attacks on each hospital. This attribution explained why many hospitals were simultaneously affected.
A ransomware attack hit a third-party healthcare IT platform used by hospitals in Romania, causing widespread outages and forcing multiple hospitals offline. The disruption affected access to medical systems and interrupted hospital operations nationwide.
Medibank announced it would not pay the ransom demanded by the attackers, citing expert advice that payment would not ensure data deletion or prevent publication. Australian officials publicly backed the decision and warned that ransom payments encourage further attacks.
Medibank said attackers accessed personal data belonging to all of its customers, covering about 9.7 million current and former customers. The company also said health claims data for roughly 480,000 customers was compromised and that all accessed data may have been stolen.
Medibank disclosed a cyberattack affecting its systems and later determined that attackers had accessed customer personal information. The incident ultimately affected current and former customers as well as some authorized representatives.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcetherecord.media
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.