Data breaches have become a defining risk of modern digital life. The Medibank breach is one of the most significant in recent memory — and if you've ever had an account with the affected service, your personal data may be circulating among cybercriminals right now.

This guide explains exactly what happened, what data was taken, and how you can check whether your information was exposed — for free, in 30 seconds.

What Happened?

The details of this breach are covered in the FAQ section below, where we answer the most important questions clearly and concisely. The key facts: who was affected, what data was taken, how attackers got in, and what the consequences have been.

Why Does This Still Matter?

Many people assume that because a breach happened years ago, the risk has passed. In reality, stolen data is sold, traded, and reused for years after a breach. Credentials from old breaches are used in credential stuffing attacks — automated attempts to log in to your other accounts using the same email and password combination.

If you reused the same password across multiple sites, one old breach can unlock dozens of your current accounts.

How to Check If You Were Affected

The fastest way is to use our free breach checker. Enter your email address and we'll scan it against known breach databases instantly — no signup required.

If your email appears in a breach, you'll see exactly which breaches affected it and what type of data was exposed. That tells you precisely where to start.

What to Do If You Were Affected

If your data was in this breach — or any breach — take these steps:

Frequently Asked Questions

When did the Medibank data breach happen?

The breach was announced in October 2022. Medibank initially indicated only limited data was accessed, then on 26 October 2022 confirmed that all 9.7 million customers' data had been compromised after the attackers shared samples as proof.

What data was stolen in the Medibank breach?

The stolen dataset included names, addresses, dates of birth, Medicare numbers, policy details, and — most critically — health claim data including diagnoses, procedures, and service locations. This included sensitive data related to mental health treatment, HIV status, drug and alcohol treatment, and pregnancy terminations.

Did Medibank pay the ransom?

No. Medibank's CEO David Koczkar announced publicly that the company would not pay the ransom. The attackers subsequently published stolen data in batches on the dark web, including lists targeting customers with HIV diagnoses and mental health records.

How do I check if my Medibank data was exposed?

Medibank contacted all affected customers directly. You can also check using your email at Scan My Shadow. Medibank set up a dedicated support service for customers whose sensitive health information was exposed.

Who was behind the Medibank breach?

Australian Federal Police attributed the attack to a Russian cybercriminal linked to the REvil ransomware group. The attacker gained access using stolen credentials from a Medibank IT service provider.

Sources

Related Reading