Public incident case study · Healthcare · Australia
Medibank Case Study
2022 cybercrime event · Regulatory proceedings ongoing
- 9.7M
- Australians in OAIC allegations
- ~520GB
- data allegedly extracted
- No MFA
- on VPN, OAIC alleges
- 2026
- OAIC proceedings continuing
Executive summary
Incident sequence
Credentials were exposed
The OAIC alleges a third-party IT worker’s Medibank admin credentials were synced to a personal device and stolen by malware.
Remote access was obtained
The OAIC alleges the adversary authenticated to Medibank’s VPN, which did not require multi-factor authentication at the time.
Alerts did not stop the activity
The OAIC alleges EDR alerts were not appropriately triaged or escalated while the actor accessed systems and extracted data.
Impact continued for years
Customer data was published on the dark web. Medibank disclosed A$46.4M, A$39.8M, A$39.7M, and A$34.9M in non-recurring cybercrime costs across FY23–FY26, totalling A$160.8M. The category includes security uplift and legal and regulatory expenditure rather than representing a definitive cash loss from the original intrusion. Medibank says the security-uplift programme is largely embedded and expects FY27 cybercrime costs below A$20M, primarily for ongoing investigations and litigation.
Full incident chronology
Incident timeline
Incident chronology.
Credential compromise
Third-party administrative credentials were allegedly stolen
The OAIC alleges that malware obtained Medibank administrative credentials after they were synchronised to a third-party IT worker’s personal device.
Remote access
The attacker allegedly authenticated to the VPN
The regulator’s timeline alleges that the stolen administrative credentials were used against a VPN configuration that did not require MFA.
- Aug–Oct 2022
Unresolved activity
Security alerts allegedly failed to stop access and extraction
The OAIC alleges that endpoint alerts were not appropriately triaged or escalated while the actor accessed systems and extracted data.
- 12–13 Oct 2022
Detection and containment
Medibank identified and contained the active compromise
The documented incident period ended as Medibank investigated the intrusion and moved into breach response and customer notification.
- Nov 2022–FY25
Data publication and cost
The consequences continued after containment
Customer information was published on the dark web, while Medibank disclosed recurring annual cybercrime-cost categories across FY23, FY24, and FY25.
FY26 financial update
Cumulative non-recurring cybercrime costs reached A$160.8 million
Medibank reported A$34.9 million for FY26, taking the disclosed FY23–FY26 total to A$160.8 million; the category includes security uplift and legal and regulatory expenditure.
- 30 Sep 2026–27 Feb 2027
Court-ordered mediation
Two proceedings received concrete mediation deadlines
The Information Commissioner civil-penalty mediation is due by 30 September 2026, followed by consolidated consumer-class-action mediation by 27 February 2027.
Lykos analysis
What organisations should learn.
Why this matters to executives and boards
The public record shows how identity, third-party access, alert handling, and sensitive-data protection can converge into long-tail cost. Medibank's A$160.8 million disclosed total through FY26 spans incident response, security uplift, and subsequent legal and regulatory expenditure, demonstrating why cyber-event cost tracking must extend well beyond initial containment.
Readiness gaps visible in the public record
The OAIC alleges lack of MFA on VPN access, compromised privileged credentials, and security alerts that were not appropriately triaged or escalated. These allegations remain before the Court. The two mediation deadlines are concrete review triggers for reassessing legal status, provisions, and the case-study record.
How Lykos helps
Turn the lesson into tested capability.
Identity and access
Validate privileged access, MFA, and account-control decisions across response-critical systems.
Explore Capability ValidationMonitoring and detection
Use threat hunting and compromise assessment to test what existing telemetry can actually prove.
Explore Threat OperationsThird-party risk
Exercise provider failure, alternate workflows, notification, and safe reconnection decisions.
Explore Tabletop ExercisesNot sure where to begin? Start with Capability Validation.
Public record
Sources
Public record reviewed 25 Aug 2026.
- OAIC takes civil penalty action against MedibankOffice of the Australian Information Commissioner · 5 Jun 2024 · Regulator
- Medibank data breach: alleged timelineOffice of the Australian Information Commissioner · 27 Jun 2024 · Regulator
- Annual Report 2023Medibank Private Limited · 24 Aug 2023 · Company report
- Annual Report 2024Medibank Private Limited · 22 Aug 2024 · Company report
- Annual Report 2025Medibank Private Limited · 21 Aug 2025 · Company report
- FY26 Results — Appendix 4E and Financial ReportMedibank Private Limited · 20 Aug 2026 · Company financial report
- Commissioner-initiated investigationsOffice of the Australian Information Commissioner · Undated · Regulator status update