Darkwebdecoded 25 Million Medicare Records Allegedly for Sale on Dark Web
Article Content
- •A hacker claims to sell 25 million Medicare records on the dark web.
- •Services Australia found issues with 47% of a sample dataset of 38 files.
- •The authenticity of the claimed dataset remains unverified, and investigations are ongoing.
A threat actor named Saotome has claimed to sell a database of 25 million Medicare records on a dark web forum, with a sample of 38 files posted on September 28, 2026. Services Australia reviewed the sample and found it contained fabricated or mismatched Medicare card information. The Australian Federal Police (AFP) and the Australian Signals Directorate (ASD) are investigating the claims, which are not linked to a previous incident involving the OpenAI Medicare portal. The authenticity of the broader dataset remains unverified, with concerns that it may be compiled from previous breaches or entirely fabricated. The sample included personal details that matched real individuals, indicating some genuine data may be present. The investigation is ongoing, and no definitive conclusions have been reached about the dataset's validity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Australian Federal Police in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What personal data is included in the dataset?
How is Services Australia responding?
What should organizations do to protect themselves?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…