Australian insurance provider Medibank Private Ltd (ASX:MPL) detected unusual activity on its networks on Wednesday, showing characteristics of a potential cyber incident.
In response to this event, the company took immediate action taking some of the critical customer-facing portals, which include the Australian Health Management (AHM) and international student policy systems, offline.
At this stage, the investigation has not revealed any evidence that any sensitive data, including customer data had been accessed during the incident
However, the company claims that it does not have “all the answers yet”.
Subsequently, Medibank has restored access to all systems that were taken down and has resumed “normal activities”.
What’s more, Medibank shares entered a trading halt following the announcement of the cyber incident, and the health insurer confirmed it would remain closed for trading as it investigates the incident.
We've made an announcement about a cyber incident. Details here: https://t.co/wkE68IG7tW
— Medibank (@medibank) October 13, 2022
Restored access to systems
Medibank CEO David Koczkar said: “I’m pleased to say our ahm and international students can now resume their normal activities after we restored access to our systems.
“I apologise for the disruption this has caused.
"Importantly, as we’ve continued to investigate all aspects of the incident, we have still found no evidence that customer data has been accessed.
"As we continue to take decisive action to safeguard our networks and systems, we will take any steps necessary to protect the data of our customers, people and other stakeholders.
"As a health company providing health insurance and health services, we hold a range of necessary personal and private customer data.
Our ahm and international students can now resume their normal activities after we restored access to our systems. We apologise for the disruption this has caused.
— Medibank (@medibank) October 14, 2022
What now?
Medibank has kicked off a forensic investigation of its information systems in order to ascertain the cause and impact of the incident.
The company has started to reach out to its customers about the incident, with around 2.8 million emails now sent to Medibank and AHM customers.
Cyber security experts have been engaged and the Australian Cyber Security Centre, regulators, government departments and other key stakeholders are being updated.
Koczkar added: “The protection of our customers and their data security is our highest priority.
"Our health services continue to be available to our customers, this includes their ability to access their health providers.
"We’ll continue to provide regular updates as we have more information.”