Australian telehealth provider Updoc notified patients that attackers gained unauthorized access to a third-party system supporting its operations, potentially exposing customer names, email addresses, and postal addresses. The company said it detected the incident on July 31, contained and isolated the affected environment, and reported that its own internal systems were not compromised.
Updoc said no health records, financial information, or payment details were affected, but warned customers to remain alert for scam attempts and fraudulent communications linked to the breach. The company has engaged external cybersecurity experts to investigate and has notified relevant law enforcement authorities, while the identity of the threat actor, the intrusion method, and the third-party provider involved have not been disclosed.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Updoc said it identified a brief period of unauthorized access to a third-party system used to support its operations. The potentially exposed data included customer names, email addresses, and postal addresses, while Updoc said its own systems and health, financial, and payment data were not affected.
Updoc notified patients that their personal information may have been accessed in the breach involving the third-party system. The company warned affected users to stay alert for scam attempts and fraudulent communications related to the incident.
After discovering the incident, Updoc launched an investigation with external cybersecurity experts, secured the affected network, and notified relevant law enforcement authorities. The company said the incident was contained and isolated with no evidence of access after the initial event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcemalware.news
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.