Australia blames Russia for harboring health insurance hackers
- Reference: 1668144609
- News link: https://www.theregister.co.uk/2022/11/11/russia_named_medibank_hack_source/
- Source link:
The release of customer data – some it containing intimate details of health services customers accessed using their insurance – came after Medibank [1]refused to pay a ransom to secure the data on grounds that doing so would not guarantee customers' safety.
"We believe that those responsible for the breach are in Russia," AFP commissioner Reece Kershaw said in a [2]statement issued on Friday afternoon, Australian time.
[3]Robin Banks crooks back at the table with fresh phish from Russia
[4]FBI: Russian hacktivists achieve only 'limited' DDoS success
[5]US Treasury thwarts DDoS attack from Russian Killnet group
[6]Upstart Ransom Cartel linked to REvil veterans
Kershaw added that the attack was conducted by "a group of loosely affiliated cyber criminals, who are likely responsible for past significant breaches in countries across the world."
That choice of words fits a description for notorious cyber gang REvil.
[7]
But Kershaw did not name any entity as responsible for the attack.
[8]
[9]
"We believe we know which individuals are responsible, but I will not be naming them," he said. "What I will say is that we will be holding talks with Russian law enforcement about these individuals."
If the attackers are in any way state-backed, that likely reflects Russian ire at Australia’s assistance for Ukraine – which has taken the form of donations of armed vehicles, humanitarian assistance, and training for Ukrainian forces. Russia has also been angered by Australia's role holding it accountable for the downing of [10]Malaysian Airlines Flight 17 which carried 38 Australian residents and citizens when it was destroyed by a Russian missile.
[11]
Or perhaps Russian president Vladimir Putin's known liking for sowing chaos just found a new form of expression at Medibank.
Australian leaders have condemned Russia's role in the incident.
Ahead of Kershaw's announcement, prime minister Anthony Albanese said Russia "should also be held accountable for the … release of information, including the very private and personal information."
[12]
Minister for cyber security Claire O'Neill labelled the attackers "cyber thugs" whose actions were "sickening and morally reprehensible." ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2022/11/07/medibank_breach_n0_ransom_payment/
[2] https://www.afp.gov.au/news-media/media-releases/statement-afp-commissioner-reece-kershaw-medibank-private-data-breach
[3] https://www.theregister.com/2022/11/08/robin_banks_phishing_service/
[4] https://www.theregister.com/2022/11/08/fbi_hacktivists_useless/
[5] https://www.theregister.com/2022/11/02/killnet_us_treasury_ddos/
[6] https://www.theregister.com/2022/10/18/revil_ransom_cartel_research/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y24rR2M5HuWnA6nUz2wycgAAAJM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y24rR2M5HuWnA6nUz2wycgAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y24rR2M5HuWnA6nUz2wycgAAAJM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2016/09/29/russian_hackers_target_mh17_journos/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y24rR2M5HuWnA6nUz2wycgAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y24rR2M5HuWnA6nUz2wycgAAAJM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
Re: And yet
Didn't you see? They're blaming Russia. Because as we all know when you're caught with your pants down, it's the intruder's fault.
Re: And yet
It wasn’t Medicare. It was Medibank.
Medicare is the public (government) health scheme and Medibank is a health insurance provider.
Re: And yet
Indeed.
My apols.
Details details details
Sure, let's go after the people who robbed the bank. But don't you think that maybe you should have installed a vault rather than a fly screen door? Shouldn't someone be held accountable for that?
I saw something in an earlier press release about how they gained access to a login that allowed them to access all 9 million records. That is a fundamental failure of:
- design
- implementation
- security
- IT governance
- QA
- legislation and/or law enforcement
- shareholder governance
But more than the fact all 9 million records were available to any account, what about field level security?
This is an enormous failure by coders/programmers turning a blind eye to poorly implemented systems and just walking home with the pay check. And all management up from there all the way to the prime ministers desk. We could look at the lack of protection for whistleblowers for a start.
Deflection
It is the Aussies fault that they were complacent about their own security systems. If my house is burgled then, if I have poor locks or no CCTV, it is my fault that I made it easy to break in.
The problem is Aussies still think that they live in isolation like it was before the Internet. They have to realise that the Internet does not respect geographical boundaries.
If course they could adopt the model used by Russia and China where everything is filtered....
Aussie are no different to the average Brit, American or any other first world country..
We allow governments and corporate to continue to accumulate data about us without regard for the consequences. We freely post the minutia of our lives on so called social media, once assembled it so easy, the things one would dumpster dive is now laid out conveniently at our finger tips to search and correlate.
And we howl when this gets abused, yet we do little to change the situation, we line up for our free email account, knowing full well its being mined. We accept governments excuses we need to store and link everything together in one place. We put identifiers on census data so we make sure everyone completes it, for want reason likely nothing more than some mindless compliance.
For years others have been warning of the consequences of these honey pots, and to those would would blame the programmers, network and systems engineers have a look at yourself.. Is everything you have done is perfect. I certainly cant make that claim.
There does need to be consequences for corporate's and government but these consequences need to be painful and serious. Not some dinky fine that is a cost of doing business. Start jailing directors and you will quickly find the C-Suite quickly finding the $$ to properly support the necessary workers and upgrades.
But we also need to accept some responsibility as individuals.. The excuse is its inconvenient, too hard, or too slow I have heard a myriad of excuse to lower barriers. Privacy matters, but over time we have allowed or been lulled into thinking you don't have the right to privacy (or in Aussies case we don't have "rights"). Maybe I should misquote Benjamin Franklin
"Those who would give up Privacy, to purchase a little convenience, deserve neither Privacy nor Safety."
Victim Blaming?
Yes maybe their security was lax - I don't know, I'm not an expert on such things, but the above comments come over very much like "She was asking for it, wearing such a short skirt.". At least medibank did the right thing by refusing to pay. If more organisations had the sense to do that the problem wouldn't exist.
Re: Victim Blaming?
The victims are the customers, not Medibank. No-one is blaming the customers.
Since this is a state sponsored attack - paying them or not paying them probably doesn't really determine their future behaviour - the state sponsor is satisfied with creating chaos, fear, uncertainty etc.
Re: Victim Blaming?
This is simply a criminal enterprise out to obtain maximum value. They are simply making an example of Medibank's refusal to pay so they can point to the consequences when they strike their next victim.
State sponsored actors tend to be information gathers, I have worked on numerous events, some criminal some state-based and the later is almost always about gathering information and access. State based actors when they strike destroy/disrupt not hold to ransom.
These folks are simply protected as Russia wont dont anything about them, likely due to kickbacks.
And yet
The Medicare CEO and Board still have their jobs.
I guess they will scapegoat some middle manager from IT for the mega cockup.