Medibank Private systems will be temporarily offline from 8.30pm AEDT Friday 9 December 2022 as the company undertakes a program to enhance security protections in the wake of a significant data loss and labelled by the Federal Minister for Cyber Security, the Hon Claire O’Neil as being one of Australia’s worst cyberattacks.
In an online statement, the company advised:
We expect the systems will be back online Sunday 11 December 2022 at the latest.
While there has been no further suspicious activity detected inside our systems since 12 October 2022, as part of the next stage of our work we are undertaking maintenance across some of our systems to further strengthen security.
This follows the recent addition of two-factor authentication in our contact centres to increase the level of security for our customers when they call for support.
We apologise for the inconvenience this operation may cause customers, but this is the next necessary phase of our ongoing work to further safeguard our network, called ‘Operation Safeguard’.
Since the cybercrime we have bolstered existing monitoring, added further detection and forensics capability across the Medibank system and network and have scaled up analytical support via specialist third parties.
This is a planned operation that involves IT security experts from Microsoft who are joining us in our Melbourne headquarters from across the Asia-Pacific region over the weekend. Given the complexity of the maintenance activities and the requirement to take our systems offline this operation has been in the planning stages for several weeks.
We are also continuing to analyse the information released by the criminal on the dark web. We can confirm that the number of customer files stolen remains unchanged. We continue to communicate to our customers, and this week we will begin to communicate with some customers who had limited provider related data stolen, such as provider number, admission date and discharge date. Like most of the data stolen, this data has been released in a raw form and is hard to understand.
During the operation customers won’t be able to access Medibank or ahm services through the website or app and HICAPS won’t be available for claiming on the spot.
Our retail stores and customer contact centre will also be closed Saturday 10 December 2022.
Amplar Health services such as our 24/7 critical health support lines will not be impacted by the operation.