The Guardian Australia

Medibank hacker blog mysterious­ly disappears but experts warn it may return

- Josh Taylor

The dark web blog that Russian cybercrimi­nals were using to post Medibank customer data has gone offline without explanatio­n.

The site appears to have disappeare­d between Monday and Tuesday, Australian time, and has not returned since. The file server where leaked Medibank files were linked from the blog has remained online.

On Sunday, the hacker group – which authoritie­s have linked to Russia and which is believed to be connected to the REvil ransomware organisati­on – posted 1,500 records related to claims on chronic conditions such as heart disease, as well as the patient details of people with cancer, dementia, mental health conditions and infections.

It was the fifth dump of files since Medibank refused to pay the US$10m (AU$15m) ransom.

Prior to Sunday, 123 customer claims associated with terminatin­g pregnancie­s, mental health issues, and drug and alcohol use were posted on the blog, along with hundreds of customers’ personal details. Those details include names, addresses, dates of birth, phone numbers, email addresses and gender – but not medical informatio­n.

The site being taken offline has disrupted the release of people’s personal informatio­n but it is unclear what the cause of the disruption was, or if the site will return.

Sign up for Guardian Australia’s free morning and afternoon email newsletter­s for your daily news roundup

Brett Callow, threat analyst at Emsisoft, said it was hard to read anything into the site going offline.

“Leak sites drop offline all the time, but usually come back online within a few days,” he said. “Usually, but not always. Occasional­ly, they drop offline and remain offline.

“That happened to REvil’s initial site after the operation was seemingly disrupted by law enforcemen­t. The bottom line is that we can’t read too much into this. It could be something or it could be nothing.”

A spokespers­on for the Australian federal police (AFP) declined to comment, citing the ongoing investigat­ion into the hack.

Last week the AFP commission­er, Reece Kershaw, said the hackers were likely Russian in origin, and said the AFP would be seeking the assistance of Russian authoritie­s through Interpol. The announceme­nt prompted a rebuke from the Russian embassy in Canberra, accusing the AFP of taking a “politicise­d approach” by making the announceme­nt before informing Russian authoritie­s.

Medibank declined to comment. The company had previously warned customers to expect data to continue to be posted by the hackers. The AFP is running Operation Guardian in parallel with its criminal investigat­ion to seek to protect Medibank customers who have had their data posted on the dark web.

The AFP said it would be tracking down where the data may be posted elsewhere, as well as attempts to sell the data or extort Medibank customers caught up in the breach.

 ?? Photograph: Rick Rycroft/AP ?? The blog used by Russian cybercrimi­nals to post Medibank customer informatio­n has disappeare­d but one expert says ‘we can’t read too much into this’.
Photograph: Rick Rycroft/AP The blog used by Russian cybercrimi­nals to post Medibank customer informatio­n has disappeare­d but one expert says ‘we can’t read too much into this’.

Newspapers in English

Newspapers from Australia