How the Medibank hack happened: one synced password and a VPN without MFA
The Medibank breach, which exposed data on 9.7 million Australians, traced back to one IT contractor's home computer. His work passwords had been synced there by a personal browser profile, and the company's remote access login asked for nothing more than a username and password.[1][2] This case file covers how those saved credentials became a 520 GB theft, what it cost Australia's largest health insurer, and the control that would have stopped it at the door.
What happened
An IT service desk worker employed by a Medibank contractor used a personal browser profile on his work computer. That profile synced his saved logins to his home computer.[2] On August 7, 2022, information-stealing malware on the home machine grabbed those saved credentials, including a standard account and an admin account that could reach most, if not all, of Medibank's systems.[1]
On August 12 the attacker began using them to log into Medibank's Microsoft Exchange server and its VPN, the secure tunnel staff use to work remotely.[1] Security software flagged suspicious behavior on August 24 and 25, but the alerts were not properly triaged or escalated.[1][2] Between August 25 and October 13, about 520 GB of data was copied out of Medibank's customer and file systems.[1]
Medibank found the intrusion in mid-October 2022, while outside specialists were looking into a separate issue on its email server.[1] The attackers demanded a ransom. On November 7, 2022, Medibank said it would not pay, and confirmed that data on 9.7 million current and former customers had been accessed.[3] The criminals then published stolen records on the dark web.[4]
How they got in
This was not a clever break-in. It was a login. Browsers can save passwords and copy them to any other device where the same personal profile is signed in. Once a work password lands on a home computer, it is only as safe as that home computer, and this one was infected with malware built to harvest saved passwords.[1][2]
The stolen credentials were enough on their own because, according to Australia's privacy regulator, Medibank's VPN accepted either a device certificate or a plain username and password. It did not require a second proof of identity such as a code on a phone.[1][2] The admin account's wide reach then let the attacker move from the VPN into the systems holding customer records.[1]
What it cost
The stolen data included names, dates of birth, addresses, phone numbers and email addresses. About 480,000 customers also had health claims data taken, including codes tied to diagnoses and procedures.[3] Medicare and passport numbers were in the haul too.[1]
Medibank's shares fell 18% after the attack, erasing about AUD 1.7 billion in market value, and the company estimated at least AUD 25 million in costs to respond.[3] On June 5, 2024, the Office of the Australian Information Commissioner filed civil penalty proceedings in federal court, alleging Medibank failed to take reasonable steps to protect personal information from March 2021 to October 2022, given its size and the sensitive data it held.[5] The filing laid out the failures described above, and Medibank said it would defend the case.[1][2]
On January 23, 2024, after an 18-month investigation by the Australian Signals Directorate and Australian Federal Police, the Australian government imposed financial sanctions and a travel ban on a Russian national over his role in the breach. The United States and United Kingdom followed.[4][1] No one has been tried.
The missing control
The missing control: multi-factor authentication on remote VPN access. Any login that lets someone reach the internal network from the internet should require a second proof, such as an app prompt or security key, on top of the password.
With multi-factor sign-in on the VPN, a password stolen from a home computer would have been close to useless. The attacker would have been stuck at the front door without the contractor's phone or key. Two other gaps made things worse: work passwords were allowed to sync to a personal device, and alerts that fired weeks before the data left were not acted on.[1][2] Either fix could have shortened the damage, but the second factor would most likely have prevented it.
What to do in your business
- Turn on multi-factor sign-in for every remote door. VPN, remote desktop, email and cloud admin panels all need a second factor. Start with anything reachable from the internet.
- Hold contractors to the same rule. Outside IT staff and service desks often have the most powerful accounts. Check their logins use multi-factor too, and give them only the access they need.
- Stop work passwords syncing to personal devices. Block personal browser profiles on work machines and keep work passwords in a company password manager.
- Separate everyday and admin accounts. Admins should use a separate account for powerful tasks, with tighter sign-in rules, so one stolen password does not open everything.
- Make sure someone answers the alarm. If your security tools send alerts, name the person or provider responsible for checking them within a day, and test that it happens.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- BleepingComputer: Scathing report on Medibank cyberattack highlights unenforced MFA
- The Record: Medibank hack, Australian government report on MFA
- The Record: Medibank says it will not pay ransom in hack that impacted 9.7 million customers
- Australian Minister for Foreign Affairs: Cyber sanctions in response to Medibank Private cyber attack
- Computer Weekly: OAIC files civil penalty action against Medibank