Public incident case study · Healthcare · Australia

Medibank Case Study

2022 cybercrime event · Regulatory proceedings ongoing

A$160.8Mcumulative disclosed non-recurring cybercrime costsA$46.4M FY23 + A$39.8M FY24 + A$39.7M FY25 + A$34.9M FY26; includes security uplift and subsequent legal and regulatory expenditure.
9.7M
Australians in OAIC allegations
~520GB
data allegedly extracted
No MFA
on VPN, OAIC alleges
2026
OAIC proceedings continuing
Executive summary

Incident sequence

  1. Credentials were exposed

    The OAIC alleges a third-party IT worker’s Medibank admin credentials were synced to a personal device and stolen by malware.

  2. Remote access was obtained

    The OAIC alleges the adversary authenticated to Medibank’s VPN, which did not require multi-factor authentication at the time.

  3. Alerts did not stop the activity

    The OAIC alleges EDR alerts were not appropriately triaged or escalated while the actor accessed systems and extracted data.

  4. Impact continued for years

    Customer data was published on the dark web. Medibank disclosed A$46.4M, A$39.8M, A$39.7M, and A$34.9M in non-recurring cybercrime costs across FY23–FY26, totalling A$160.8M. The category includes security uplift and legal and regulatory expenditure rather than representing a definitive cash loss from the original intrusion. Medibank says the security-uplift programme is largely embedded and expects FY27 cybercrime costs below A$20M, primarily for ongoing investigations and litigation.

Full incident chronology

Incident timeline

Incident chronology.

  1. Credential compromise

    Third-party administrative credentials were allegedly stolen

    The OAIC alleges that malware obtained Medibank administrative credentials after they were synchronised to a third-party IT worker’s personal device.

  2. Remote access

    The attacker allegedly authenticated to the VPN

    The regulator’s timeline alleges that the stolen administrative credentials were used against a VPN configuration that did not require MFA.

  3. Aug–Oct 2022

    Unresolved activity

    Security alerts allegedly failed to stop access and extraction

    The OAIC alleges that endpoint alerts were not appropriately triaged or escalated while the actor accessed systems and extracted data.

  4. 12–13 Oct 2022

    Detection and containment

    Medibank identified and contained the active compromise

    The documented incident period ended as Medibank investigated the intrusion and moved into breach response and customer notification.

  5. Nov 2022–FY25

    Data publication and cost

    The consequences continued after containment

    Customer information was published on the dark web, while Medibank disclosed recurring annual cybercrime-cost categories across FY23, FY24, and FY25.

  6. FY26 financial update

    Cumulative non-recurring cybercrime costs reached A$160.8 million

    Medibank reported A$34.9 million for FY26, taking the disclosed FY23–FY26 total to A$160.8 million; the category includes security uplift and legal and regulatory expenditure.

  7. 30 Sep 2026–27 Feb 2027

    Court-ordered mediation

    Two proceedings received concrete mediation deadlines

    The Information Commissioner civil-penalty mediation is due by 30 September 2026, followed by consolidated consumer-class-action mediation by 27 February 2027.

Lykos analysis

What organisations should learn.

Why this matters to executives and boards

The public record shows how identity, third-party access, alert handling, and sensitive-data protection can converge into long-tail cost. Medibank's A$160.8 million disclosed total through FY26 spans incident response, security uplift, and subsequent legal and regulatory expenditure, demonstrating why cyber-event cost tracking must extend well beyond initial containment.

Readiness gaps visible in the public record

The OAIC alleges lack of MFA on VPN access, compromised privileged credentials, and security alerts that were not appropriately triaged or escalated. These allegations remain before the Court. The two mediation deadlines are concrete review triggers for reassessing legal status, provisions, and the case-study record.

How Lykos helps

Turn the lesson into tested capability.

Monitoring and detection

Use threat hunting and compromise assessment to test what existing telemetry can actually prove.

Explore Threat Operations

Not sure where to begin? Start with Capability Validation.

Public record

Sources

Public record reviewed 25 Aug 2026.

  1. OAIC takes civil penalty action against MedibankOffice of the Australian Information Commissioner · 5 Jun 2024 · Regulator
  2. Medibank data breach: alleged timelineOffice of the Australian Information Commissioner · 27 Jun 2024 · Regulator
  3. Annual Report 2023Medibank Private Limited · 24 Aug 2023 · Company report
  4. Annual Report 2024Medibank Private Limited · 22 Aug 2024 · Company report
  5. Annual Report 2025Medibank Private Limited · 21 Aug 2025 · Company report
  6. FY26 Results — Appendix 4E and Financial ReportMedibank Private Limited · 20 Aug 2026 · Company financial report
  7. Commissioner-initiated investigationsOffice of the Australian Information Commissioner · Undated · Regulator status update