A hacker who leaked personal data under titles including ‘boozy’, ‘HIV’ and ‘abortions’ could have been stopped by basic security measures, a class action alleges.

A hacker moved undetected through Medibank’s network for weeks despite multiple warning flags being raised, a court has been told.
The health insurer is facing both a class action by impacted customers and civil penalties brought by the privacy watchdog over the 2022 hack.
After Medibank declined to pay a ransom, personal data was leaked on the dark web under malicious file names including boozy, STD and psycho.
Federal Court Justice Jonathan Beach heard evidence on Friday to help decide whether the cases will be held jointly or as separate trials.
A lawyer for the class action argued it was in the interests of justice to hear the cases together.
“The technical issues here overlap and intersect at multiple stages … in terms of the architecture of Medibank’s cybersecurity systems (and) the control deficiencies in them,” Wendy Harris KC said.
Outside access was originally gained to Medibank’s network in August 2022, via the personal computer of a third-party contractor.
“What follows is not simply someone entering a network and downloading a database – it’s a progression through the network over a period of weeks,” Harris told the court.
Throughout the breach, several alerts were raised which were not dealt with by Medibank, she said.
“Medibank’s systems, as deficient as they were, were throwing up the canary warnings, but those were effectively ignored,” she said.
“Some weren’t even triaged. Others were reviewed and just closed as false positives or benign activity.”
Once within the system, the hacker gained increasingly higher-level access and moved laterally through Medibank’s network, ultimately extracting 529 gigabytes of customer data.
Data was released under file names including a good list and naughty list, as well as abortions, boozy, psycho, HIV, STD and hepatitis.
“The nature of those publications gives some indication why this proceeding matters to the people whose information Medibank held,” Harris said.
The class action alleges four core failures by Medibank to protect its customers’ data, any of which it says could have prevented the breach had they been in place at the time.
The four failures regarded not having multi-factor authentication in place, as well as failures to document changes to IT assets and lapses in security testing and monitoring.
In response, Neil Young KC called the class action a “total mess”, saying it went well beyond the Office of the Australian Information Commissioner’s case in its allegations of cybersecurity failures.
“Their case has dramatically altered in the last four weeks,” said Young, who is representing Medibank in both matters.
“There are many new allegations of breach.
“In order for us to address those new allegations, that’s going to require time.”
Justice Beach adjourned the matter until October 16, in part to allow the class action party to consolidate its statement of claim.
Want to see more stories from InDaily SA in your Google search results?