Massive medication data breach affects almost 13 million Australians

Close-up adult hand typing on laptop - GettyImages

Close-up adult hand typing on laptop Source: Getty / Bill Hinton

Get the SBS Audio app

Other ways to listen

Almost 13 million Australians have been caught up in one of the country's largest cyber-attacks.The electronic prescriptions provider has revealed personal and health-related data of almost 13 million Australians has been impacted in one of the country's largest cyber-attacks.


Listen to Australian and world news, and follow trending topics with

TRANSCRIPT

In one of the biggest cyber breaches in the nation's history, nearly 13 million Australian have had their personal data stolen from MediSecure.

Prime Minister Anthony Albanese says he understands people are concerned.

“I understand that many Australians will be very concerned about this data breach that affects up to half of the Australian population. This is a very significant cyber event. It's not the first and it won't be the last.”

MediSecure promised prescriptions for medications, sent safely and securely.

But between March 2019 and November 2023, data from 12.9 million Australians was stolen.

MediSecure says it was made aware of the breach in April, with the public first notified in May - with some of the information up for sale on a Russian hacking site.

The advice - assume you’re impacted, and don’t go looking for the information online, says National Cyber Security Coordinator Michelle McGuiness.

“Nobody should be going on the dark web and looking for this information. It not only feeds the criminal model that inspires criminals to turn this into a financial activity, but it also can be a criminal offence to deal in stolen data.”

The leaked information includes Medicare numbers, information about medications, the dose, and reason it was prescribed.

Names, birthdays, contact information, and home addresses were also stolen.

Ms McGuiness says be wary of people and organisations contacting you.

“If you receive anyone reaching out, whether it be text or email or phone call, I encourage you to decline that reach out. And if you think it's legitimate, pursue your own research and find an independent phone number or email and reach out to confirm with that entity.”

MediSecure went into administration last month, saying its unable to identify the specific impacted individuals despite making all reasonable efforts to do so.

The AFP is now investigating.

Ms McGuiness says there are ways to protect yourself online.

“Accept multi factor authentication, number one. Number two, update your software. Every time a new software update is released, it's typically around a security vulnerability that is known. Update your software. And three, ensure you update your passwords and keep them unique across each of your accounts.”

The Prime Minister promising, the government is taking cyber security seriously.

“We need to be ever vigilant. Cyber security is a threat to individuals, to corporations, most importantly to their customers, but to us as a nation as well. That's why we've ramped up our funding of the Australian Signals Directorate. That's why we have a cyber security taskforce working with the business community on these issues.”

More information on how to protect your data is available online - at homeaffairs.gov.au and cyber.gov.au.


Share