Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatransomware-group-operationthird-party-vendor-breachoperational-disruption

Ransomware and Data Breaches Disrupt Healthcare Providers in Australia and Romania

Updated 1mo agoFirst seen May 25, 20264 sources

Medibank said attackers accessed personal data belonging to all of its customers and some authorized representatives, affecting about 9.7 million current and former customers. The Australian health insurer said the compromised information included identifying details and health claims data for roughly 480,000 customers, and warned that all accessed data may have been stolen. Medibank later said it would not pay the ransom, citing expert advice that payment would not ensure the return of data or prevent its publication, while Australian officials backed the decision and warned that ransom payments fuel further extortion.

In Romania, hospitals were forced offline after a ransomware attack hit a healthcare IT platform used by multiple medical facilities, disrupting operations across the country. Reporting indicated the crisis was linked to a third-party incident, underscoring how attacks on shared service providers can cascade across healthcare organizations. Together, the incidents highlight how cybercriminals are targeting healthcare entities through both direct intrusions and attacks on critical external platforms, exposing sensitive patient data and interrupting care delivery.

Share:
Ransomware and Data Breaches Disrupt Healthcare Providers in Australia and Romania
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 14, 20242y ago

Romanian hospital outages linked to third-party incident

Reporting the following day clarified that the Romanian healthcare disruption was tied to a ransomware incident at a third-party IT provider rather than separate attacks on each hospital. This attribution explained why many hospitals were simultaneously affected.

Feb 13, 20242y ago

Ransomware attack on Romanian healthcare IT platform disrupts hospitals

A ransomware attack hit a third-party healthcare IT platform used by hospitals in Romania, causing widespread outages and forcing multiple hospitals offline. The disruption affected access to medical systems and interrupted hospital operations nationwide.

Nov 7, 20224y ago

Medibank refuses to pay ransom after breach

Medibank announced it would not pay the ransom demanded by the attackers, citing expert advice that payment would not ensure data deletion or prevent publication. Australian officials publicly backed the decision and warned that ransom payments encourage further attacks.

Oct 26, 20224y ago

Medibank confirms all customer personal data was accessed

Medibank said attackers accessed personal data belonging to all of its customers, covering about 9.7 million current and former customers. The company also said health claims data for roughly 480,000 customers was compromised and that all accessed data may have been stolen.

Medibank detects cyberattack and unauthorized access to customer data

Medibank disclosed a cyberattack affecting its systems and later determined that attackers had accessed customer personal information. The incident ultimately affected current and former customers as well as some authorized representatives.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Ransomware and Data Breaches Disrupt Healthcare Providers in Australia and Romania | Mallory