Millions of Australians hit by prescription cyber hack

A trove of health and personal data was stolen by hackers from prescriptions provider MediSecure. (Dave Hunt/AAP PHOTOS)

Hackers stole personal data including the health information of nearly 13 million Australians earlier this year, making it one of the nation's biggest cyber attacks.

Electronic prescriptions provider MediSecure on Thursday revealed 12.9 million customers had their data stolen, an unknown amount of which has been uploaded to the dark web.

The company first became aware of the breach on April 13 when suspected ransomware was discovered on a server containing the sensitive personal and health data, then publicly confirmed the attack in May.

MediSecure said Australians who used the company's prescription delivery service from March 2019 to November 2023 were impacted, their data stolen by a malicious third-party actor.

Among the 6.5 terabytes of data stolen are names, dates of birth, addresses, phone numbers, Medicare numbers, prescription information and the reasons for the medication.

A sample of personal information has been exposed on the dark web but the company said it was unable to identify specific individuals impacted due to the complexity of the data and the cost of doing so.

The federal government was not aware of publication of the full data set, National Cyber Security Coordinator Lieutenant General Michelle McGuinness said on X, formerly Twitter. 

"No one should go looking for or access stolen sensitive or personal information from the dark web," Lt Gen McGuinness said on Thursday. 

"This activity only feeds the business model of cyber criminals and can be a criminal offence."

People who go searching for their information on the dark web risk committing cybercrime if they deal with stolen personal information and can attract a five-year jail term.

"I understand many Australians will be concerned about the scale of this breach. I encourage everyone, whether impacted in this incident or not, to be alert to being targeted in scams," Lt Gen McGuiness said.

Cyber Security Coordinator Lieutenant General Michelle McGuinness
Lieutenant General Michelle McGuinness warned people against searching for the stolen information.

MediSecure was one of two electronic prescription delivery services until late 2023, with the Australian government awarding the service exclusively to eRx Script Exchange.

The company appointed liquidators and went into administration in June, and is not part of Australia's digital health network.

National prescription delivery service eRx is not affected by this cyber incident, the government confirmed.

"Consumers can continue to access medicines safely, and healthcare providers can still prescribe and dispense as usual," it said.

Impacting almost half of the population, the MediSecure breach makes it one of the largest cyber attacks in Australia.

An attack on Optus in September 2022 affected 10 million users and another in October at Medibank impacted about 9.7 million people.

Those impacted by the cyber hack may see an increase in phishing, identity-related crime and cyber scam activities. 

The national cyber security coordinator urged them to keep a lookout lookout for scams referencing the MediSecure data breach, and do not respond to unsolicited contact that references the company's data breach.

License this article

What is AAPNews?

For the first time, Australian Associated Press is delivering news straight to the consumer.

No ads. No spin. News straight-up.

Not only do you get to enjoy high-quality news delivered straight to your desktop or device, you do so in the knowledge you are supporting media diversity in Australia.

AAP Is Australia’s only independent newswire service, free from political and commercial influence, producing fact-based public interest journalism across a range of topics including politics, courts, sport, finance and entertainment.

What is AAPNews?
The Morning Wire

Wake up to AAPNews’ morning news bulletin delivered straight to your inbox or mobile device, bringing you up to speed with all that has happened overnight at home and abroad, as well as setting you up what the day has in store.

AAPNews Morning Wire
AAPNews Breaking News
Breaking News

Be the first to know when major breaking news happens.


Notifications will be sent to your device whenever a big story breaks, ensuring you are never in the dark when the talking points happen.

Focused Content

Enjoy the best of AAP’s specialised Topics in Focus. AAP has reporters dedicated to bringing you hard news and feature content across a range of specialised topics including Environment, Agriculture, Future Economies, Arts and Refugee Issues.

AAPNews Focussed Content
Subscription Plans

Choose the plan that best fits your needs. AAPNews offers two basic subscriptions, all billed monthly.

Once you sign up, you will have seven days to test out the service before being billed.

AAPNews Full Access Plan
Full Access
AU$10
  • Enjoy all that AAPNews has to offer
  • Access to breaking news notifications and bulletins
  • Includes access to all AAPNews’ specialised topics
Join Now
AAPNews Student Access Plan
Student Access
AU$5
  • Gain access via a verified student email account
  • Enjoy all the benefits of the ‘Full Access’ plan at a reduced rate
  • Subscription renews each month
Join Now
AAPNews Annual Access Plan
Annual Access
AU$99
  • All the benefits of the 'Full Access' subscription at a discounted rate
  • Subscription automatically renews after 12 months
Join Now

AAPNews also offers enterprise deals for businesses so you can provide an AAPNews account for your team, organisation or customers. Click here to contact AAP to sign-up your business today.

SEVEN DAYS FREE
Download the app
Download AAPNews on the App StoreDownload AAPNews on the Google Play Store