Indailysa.Au Medibank Faces Class Action Over 2022 Data Breach
Article Content
- •Medibank is facing a class action lawsuit and civil penalties over a 2022 data breach.
- •The breach involved a hacker moving undetected for weeks, leading to the leak of 529 GB of data.
- •Key security failures cited include the lack of multi-factor authentication and inadequate monitoring.
Medibank is currently facing a class action lawsuit and civil penalties from the privacy watchdog following a significant data breach in 2022. A hacker reportedly moved undetected through Medibank's network for weeks, exploiting multiple security deficiencies and ignoring alerts raised by the system. The breach resulted in the leak of 529 gigabytes of sensitive customer data, which was published on the dark web under various provocative file names. The class action alleges that Medibank failed to implement security measures, including multi-factor authentication and proper monitoring of IT changes. The Federal Court is deliberating whether to consolidate the class action and the privacy watchdog's case. Medibank's legal representation has criticized the class action as disorganized and evolving rapidly in its claims.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Medibank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data was leaked?
What security measures were lacking?
What is the current status of the lawsuit?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…