
On 5 June 2024, the Australian Information Commissioner commenced civil penalty proceedings in the Australian Federal Court against Medibank Private Limited (an Australian health insurance provider) in relation to an October 2022 data breach.
On 25 October 2022, Medibank notified the Office of the Australian Information Commissioner (OAIC) of a data breach concerning sensitive personal information of 9.7m Australians (representing approximately 37% of Australia’s total population). As a result of a cyber-attack, malicious actors had gained access to a vast library of customer data which included identity details, government identifiers and medical and insurance records. Over the course of a number of weeks, the malicious actors ‘leaked’ sensitive personal information of Medibank customers and other impacted individuals onto the dark-web in the course of pursuing cyber ransoms from the major insurance-provider.








