Medibank's Cyberblunder Analyzed

Catch up on the recent Medibank cyberattack report and it's implications.

In partnership with

Firefly

Help-Desk Woes 💣️ 

This Wednesday’s article is a personal doozy. I’ve seen these situations happen first hand in Healthcare and with the end of an investigation… I just had to peel back the cause of this issue. The mistakes and lesson here might just save you or a friend in the future!

Your Brilliant Business Idea Just Got a New Best Friend

Got a business idea? Any idea? We're not picky. Big, small, "I thought of this in the shower" type stuff–we want it all. Whether you're dreaming of building an empire or just figuring out how to stop shuffling spreadsheets, we're here for it.

Our AI Ideas Generator asks you 3 questions and emails you a custom-built report of AI-powered solutions unique to your business.

Imagine having a hyper-intelligent, never-sleeps, doesn't-need-coffee AI solutions machine at your beck and call. That's our AI Ideas Generator. It takes your business conundrum, shakes it up with some LLM magic and–voila!--emails you a bespoke report of AI-powered solutions.

Outsmart, Outpace, Outdo: Whether you're aiming to leapfrog the competition or just be best-in-class in your industry, our custom AI solutions have you covered.

A Support Blunder

Woops… shouldn’t have turned that feature off!

There is a fear that sits somewhere in the mind of every support tech that they could be the next trigger to a front of page cyberattack. While this attack is not recent, we’ve finally learned that just one unfortunate tech might be the reason this attack happened.

Two years ago, Alexander Gennadievich Ermakov, a Russian national, launched a cyberattack on the Australian Medibank system. This led to more then 9.7 million Australian natives having their information compromised.

This devastated the public trust in both the system and their current level of cybersecurity. I am a personal victim of identity theft, the struggle these Austrialians now face is quite an uphill battle.

Unfortunately, this attack succeeded because of something that is now so common place. A support desk technician logged into his VPN without a MFA or two-factor authentication.

A Lesson In Defense

Iterating off our above section, we’re well versed with multi-factor authenticators. There is many different types, phone calls, apps with constantly generating codes, simple captchas. This feature in cybersecurity did wonders on release but now with time, flaws still persist even with this model of protection.

The culprit and point of origin for this attack was due to specifically “browser-stored Medibank credentials” on a support technicians work computer. This provided our Russian national elevated privileges and access to the Medibank’s Microsoft Exchange server and its Palo Alto VPN.

Needless to say… it was a disaster. A breach of that magnitude was enabled by the tech debt that Medibank was actually alerted to months prior in August. They knew a 2-factor authenticator would improve security and yet decided to be negligent.

Defense in the modern world is a never ending vigilant task.

This is your lesson, never spare an expense on a proactive defense. You will save yourself, company or friends thousands if not millions of dollars in damages. This example, 9.7 million users and over 520 gigabytes of data stolen and now they face fines costing as much as 21 trillion dollars.

Constantly be testing your systems defenses, always put yourself in the shoes of an attacker, isolate your systems, and enforce redundancy at every level. Understandably, cost will rise but it’s cheaper to pay 5 million for a upgrade of your cybersecurity then 21 trillion in fines.

I’ve taken the liberty of grabbing the including the report that OAIC recently published as it now pursues such massive fines again Medibank.

Checking in…

Hey everyone, we wanted to say thank you to the vast explosion of subscribers we’ve had recently. Your eagerness and excitement is elating us to push harder on finding things you like to know. We’re noticing a strong trend of focus from everyone on Cybersecurity and AI. Notice, we’re referring below to what you’d like to see more of. We will not be giving up either subject, simply honing in and having more posts monthly based off your interests.

What Do You Prefer To See?

We're building our content plan and want to see what interests everyone!

Login or Subscribe to participate in polls.

Thanks for tuning in everyone, remember to subscribe, share our newsletter and follow us on our social media! We love to hear from you guys!

Reply

or to participate.