Current and former Medibank, ahm and international customers whose data was stolen.
Centennial Lawyers is accepting registrations for updates about the OAIC representative complaint concerning the 2022 Medibank data breach, which affected current and former Medibank Private and ahm customers whose personal and health data was stolen and published on the dark web. Register below to receive updates about this complaint.
Only an email address or mobile number is requested at this stage. You do not need to provide your name, documents or details about your circumstances to receive updates.
Current and former Medibank, ahm and international customers whose data was stolen.
Medibank detected unusual activity on 12–13 October 2022 and notified the ASX.
Sensitive health claims data including diagnosis codes, treatments and procedures.
Centennial Lawyers is accepting registrations for updates about the OAIC representative complaint.
This keeps communications linked to the correct matter record. Official email communications are sent only from contact@medibankdatabreach.com.au.
In October 2022, a cybercriminal gained access to Medibank’s systems and exfiltrated data belonging to current and former Medibank Private, ahm and international student health cover customers. After Medibank refused to pay the ransom, the attacker published the stolen data on the dark web beginning in November 2022.
The exposed data included names, dates of birth, addresses, phone numbers, email addresses, Medicare card numbers, passport numbers and — for approximately 480,000 customers — sensitive health claims information including diagnosis codes, treatment details and provider names.
The timeline separates confirmed public facts from matters that remain under legal proceedings.
A cybercriminal obtained Medibank employee credentials via malware and used them to access Medibank’s corporate VPN and internal systems.
Medibank detected unusual activity on its systems and made an ASX disclosure. The OAIC was notified under the Notifiable Data Breaches scheme.
Medibank confirmed that data belonging to 9.7 million current and former customers had been stolen, including sensitive health claims data for approximately 480,000 customers.
After Medibank refused to pay the ransom demand, the attacker began releasing stolen customer data on the dark web, including sensitive health records.
The Australian Government, in coordination with the US and UK, identified and sanctioned Russian national Aleksandr Ermakov as the perpetrator of the cyberattack.
Centennial Lawyers is accepting registrations from current and former Medibank and ahm customers who wish to receive updates about the OAIC representative complaint concerning the Medibank data breach.
The data stolen varies by customer. You do not need to confirm the affected data to register for updates.
The following are separate from the OAIC representative complaint involving Centennial Lawyers and Maurice Blackburn. They are listed here for information only. Centennial Lawyers does not conduct these matters, and registering on this site does not enrol you in them.
This is the official registration and information site operated by Centennial Lawyers (CENTENNIAL LAWYERS PTY LTD, ABN 54 653 103 818, ACN 653 103 818) for its Medibank data breach OAIC representative complaint. Maurice Blackburn is a separate participant in the OAIC representative complaint and does not operate this site or this registration. medibankdatabreach.com.au is the canonical domain for Centennial Lawyers' registration. To keep your details linked to Centennial Lawyers' matter record, please register only through this site. Official email correspondence is sent only from contact@medibankdatabreach.com.au.
Provide one contact method only. Get OAIC representative complaint updates — no name, circumstances or documents needed.
In August 2022 a cybercriminal obtained Medibank employee credentials via malware and used them to access Medibank’s internal systems. By October 2022, Medibank detected unusual activity and notified the ASX and the OAIC. The attacker exfiltrated data belonging to approximately 9.7 million current and former Medibank Private, ahm and international student health cover customers. After Medibank refused to pay the ransom, the attacker published stolen customer data on the dark web from November 2022 onwards.
You may be affected if you were a current or former Medibank Private customer, an ahm customer, or an international student health cover customer whose data was held by Medibank at the time of the breach. Approximately 480,000 customers had sensitive health claims data exposed, including diagnosis codes, treatment details and mental health records.
Stolen data included names, dates of birth, addresses, phone numbers, email addresses, Medicare card numbers, and passport numbers. For approximately 480,000 customers, sensitive health claims data was also exposed — including diagnosis codes, medical procedure codes, treatment details, health provider names, mental health and drug and alcohol treatment records, and pregnancy termination records.
Centennial Lawyers and Maurice Blackburn are involved in a representative complaint made to the Office of the Australian Information Commissioner (OAIC) concerning the Medibank data breach. Registering on this site keeps you updated about that representative complaint. This is separate from two other matters listed for information only: the OAIC’s own civil penalty proceedings against Medibank in the Federal Court (a regulator-led action that individuals do not need to join), and the consolidated Federal Court class action (operated independently). Registering here does not enrol you in either of those.
Centennial Lawyers and Maurice Blackburn are involved in the representative complaint made to the OAIC on behalf of affected Medibank and ahm customers. Centennial Lawyers is a plaintiff law firm; Maurice Blackburn is a national plaintiff litigation firm. They will provide updates to registered individuals as the complaint progresses. Registration does not create a solicitor–client relationship or confirm eligibility.
No. Registration for updates is completely free and carries no obligation. You will not be charged anything, and registering does not commit you to any legal action or create a solicitor–client relationship.
You will receive updates about the OAIC representative complaint as it progresses. You do not need to provide your name, documents or details about your circumstances at this stage. If the complaint advances or a related step becomes relevant, you will be notified and given the opportunity to provide further information if you choose to.
Your contact detail is collected solely to send you updates about the OAIC representative complaint and is handled in accordance with the Privacy Act 1988 (Cth). Only a single contact method (email address or mobile number) is required at registration stage. Your information will not be used for any purpose other than complaint updates without your separate consent. Full details are set out in the Privacy Policy and Collection Notice linked in the footer.
Updates on the OAIC representative complaint involving Centennial Lawyers and Maurice Blackburn, plus key developments in separate, independently operated proceedings about the breach.
Centennial Lawyers and Maurice Blackburn are involved in a representative complaint made to the OAIC concerning the 2022 Medibank data breach. Affected current and former Medibank Private and ahm customers are encouraged to register for updates about this complaint. Only a single contact method is required at this stage.
The Office of the Australian Information Commissioner filed civil penalty proceedings against Medibank Private Limited in the Federal Court of Australia in June 2024. The OAIC alleges serious and repeated interferences with the privacy of approximately 9.7 million Australians in contravention of the Privacy Act 1988 (Cth). Penalties under the Privacy Act can be significant.
In January 2024, the Australian Government — in coordination with the United States and United Kingdom — publicly identified and sanctioned Russian national Aleksandr Ermakov as the individual responsible for the Medibank cyberattack. This was the first time Australia had imposed a cyber sanction on an individual.
In August 2023 the Federal Court of Australia consolidated the competing class actions arising from the Medibank data breach into a single proceeding. This consolidated class action is separate from and independent of the OAIC representative complaint on this site — registering here does not join it.
Medibank confirmed on 7 November 2022 that data belonging to 9.7 million current and former customers had been stolen. After Medibank refused to pay the ransom, the attacker began publishing stolen data on the dark web from 9 November 2022, including sensitive health records for approximately 480,000 customers.
The primary public hub for the breach timeline, affected groups, and registration for updates on the OAIC representative complaint involving Centennial Lawyers and Maurice Blackburn.
The wider registry of Australian class actions and legal investigations, maintained by ClassActions.com.au as the authoritative public resource.