Official matter website: MedibankDataBreach.com.au
Medibank Data Breach
Public information and OAIC representative complaint registration
Register for updates
Registrations open

Medibank Data Breach

Centennial Lawyers is accepting registrations for updates about the OAIC representative complaint concerning the 2022 Medibank data breach, which affected current and former Medibank Private and ahm customers whose personal and health data was stolen and published on the dark web. Register below to receive updates about this complaint.

Register for updates Review the known facts

Only an email address or mobile number is requested at this stage. You do not need to provide your name, documents or details about your circumstances to receive updates.

Customers affected
9.7 million

Current and former Medibank, ahm and international customers whose data was stolen.

Breach detected
October 2022

Medibank detected unusual activity on 12–13 October 2022 and notified the ASX.

Health records stolen
~480,000

Sensitive health claims data including diagnosis codes, treatments and procedures.

Registration status
Registrations open

Centennial Lawyers is accepting registrations for updates about the OAIC representative complaint.

Official communication channels

Use the website forms for all registrations and enquiries

This keeps communications linked to the correct matter record. Official email communications are sent only from contact@medibankdatabreach.com.au.

Fraud and document warning
We will not ask by unsolicited email for passwords, banking credentials or identity document copies. Do not email sensitive documents unless requested through an authorised portal communication.
Why you may be affected

9.7 million Medibank and ahm customers had their data stolen and published online

In October 2022, a cybercriminal gained access to Medibank’s systems and exfiltrated data belonging to current and former Medibank Private, ahm and international student health cover customers. After Medibank refused to pay the ransom, the attacker published the stolen data on the dark web beginning in November 2022.

The exposed data included names, dates of birth, addresses, phone numbers, email addresses, Medicare card numbers, passport numbers and — for approximately 480,000 customers — sensitive health claims information including diagnosis codes, treatment details and provider names.

Incident chronology

Verified public timeline

The timeline separates confirmed public facts from matters that remain under legal proceedings.

  1. August 2022
    Attacker

    Initial access obtained

    A cybercriminal obtained Medibank employee credentials via malware and used them to access Medibank’s corporate VPN and internal systems.

  2. 12–13 October 2022
    Medibank / ASX

    Breach detected and disclosed

    Medibank detected unusual activity on its systems and made an ASX disclosure. The OAIC was notified under the Notifiable Data Breaches scheme.

  3. 7 November 2022
    Medibank

    Full extent revealed — 9.7 million customers

    Medibank confirmed that data belonging to 9.7 million current and former customers had been stolen, including sensitive health claims data for approximately 480,000 customers.

  4. 9 November 2022 onwards
    Attacker / Dark web

    Stolen data published on dark web

    After Medibank refused to pay the ransom demand, the attacker began releasing stolen customer data on the dark web, including sensitive health records.

  5. March 2024
    Australian Government

    Attacker identified and sanctioned

    The Australian Government, in coordination with the US and UK, identified and sanctioned Russian national Aleksandr Ermakov as the perpetrator of the cyberattack.

  6. Current
    Centennial Lawyers

    OAIC representative complaint — registrations open

    Centennial Lawyers is accepting registrations from current and former Medibank and ahm customers who wish to receive updates about the OAIC representative complaint concerning the Medibank data breach.

Information involved

What types of data were stolen?

The data stolen varies by customer. You do not need to confirm the affected data to register for updates.

Personal and identity information

  • Names
  • Dates of birth
  • Addresses
  • Phone numbers and email addresses
  • Medicare card numbers
  • Passport numbers and visa details

Sensitive health claims data

  • Diagnosis codes
  • Medical procedure codes
  • Treatment and service details
  • Health provider names
  • Mental health, drug and alcohol treatment records
  • Pregnancy termination records

Health insurance information

  • Policy details
  • Membership numbers
  • Benefit and claims history
Who is affected

Individuals who may be eligible

  • Current or former Medibank Private customers
  • Current or former ahm customers
  • International student health cover customers
  • Customers whose sensitive health claims data was published on the dark web
  • Customers notified by Medibank of the breach
  • Anyone whose Medicare number, passport or personal data was stolen
Related proceedings — separate matters

Other proceedings about the breach

The following are separate from the OAIC representative complaint involving Centennial Lawyers and Maurice Blackburn. They are listed here for information only. Centennial Lawyers does not conduct these matters, and registering on this site does not enrol you in them.

  • OAIC civil penalty proceedings (Federal Court). In June 2024 the Office of the Australian Information Commissioner filed civil penalty proceedings against Medibank in the Federal Court under the Privacy Act 1988 (Cth). This is a regulator-led action; individuals do not need to take any step to be covered by it.
  • Consolidated Federal Court class action. In August 2023 the Federal Court consolidated competing class actions arising from the breach into a single proceeding, operated independently. Registering here is not joining that class action.
Official registration site

This is the official registration and information site operated by Centennial Lawyers (CENTENNIAL LAWYERS PTY LTD, ABN 54 653 103 818, ACN 653 103 818) for its Medibank data breach OAIC representative complaint. Maurice Blackburn is a separate participant in the OAIC representative complaint and does not operate this site or this registration. medibankdatabreach.com.au is the canonical domain for Centennial Lawyers' registration. To keep your details linked to Centennial Lawyers' matter record, please register only through this site. Official email correspondence is sent only from contact@medibankdatabreach.com.au.

Minimal registration

Register for complaint updates

Provide one contact method only. Get OAIC representative complaint updates — no name, circumstances or documents needed.

Do you believe you have been impacted by the data breach?

No name, address or documents are requested at this stage.

Frequently asked questions

Common questions about the Medibank OAIC representative complaint

What happened in the Medibank data breach?

In August 2022 a cybercriminal obtained Medibank employee credentials via malware and used them to access Medibank’s internal systems. By October 2022, Medibank detected unusual activity and notified the ASX and the OAIC. The attacker exfiltrated data belonging to approximately 9.7 million current and former Medibank Private, ahm and international student health cover customers. After Medibank refused to pay the ransom, the attacker published stolen customer data on the dark web from November 2022 onwards.

Who is affected?

You may be affected if you were a current or former Medibank Private customer, an ahm customer, or an international student health cover customer whose data was held by Medibank at the time of the breach. Approximately 480,000 customers had sensitive health claims data exposed, including diagnosis codes, treatment details and mental health records.

What data was exposed?

Stolen data included names, dates of birth, addresses, phone numbers, email addresses, Medicare card numbers, and passport numbers. For approximately 480,000 customers, sensitive health claims data was also exposed — including diagnosis codes, medical procedure codes, treatment details, health provider names, mental health and drug and alcohol treatment records, and pregnancy termination records.

What is the OAIC representative complaint and how is it different from other proceedings?

Centennial Lawyers and Maurice Blackburn are involved in a representative complaint made to the Office of the Australian Information Commissioner (OAIC) concerning the Medibank data breach. Registering on this site keeps you updated about that representative complaint. This is separate from two other matters listed for information only: the OAIC’s own civil penalty proceedings against Medibank in the Federal Court (a regulator-led action that individuals do not need to join), and the consolidated Federal Court class action (operated independently). Registering here does not enrol you in either of those.

Who is involved in the representative complaint?

Centennial Lawyers and Maurice Blackburn are involved in the representative complaint made to the OAIC on behalf of affected Medibank and ahm customers. Centennial Lawyers is a plaintiff law firm; Maurice Blackburn is a national plaintiff litigation firm. They will provide updates to registered individuals as the complaint progresses. Registration does not create a solicitor–client relationship or confirm eligibility.

Does it cost anything to register?

No. Registration for updates is completely free and carries no obligation. You will not be charged anything, and registering does not commit you to any legal action or create a solicitor–client relationship.

What happens after I register?

You will receive updates about the OAIC representative complaint as it progresses. You do not need to provide your name, documents or details about your circumstances at this stage. If the complaint advances or a related step becomes relevant, you will be notified and given the opportunity to provide further information if you choose to.

How is my personal information handled?

Your contact detail is collected solely to send you updates about the OAIC representative complaint and is handled in accordance with the Privacy Act 1988 (Cth). Only a single contact method (email address or mobile number) is required at registration stage. Your information will not be used for any purpose other than complaint updates without your separate consent. Full details are set out in the Privacy Policy and Collection Notice linked in the footer.

News and updates

Updates and related developments

Updates on the OAIC representative complaint involving Centennial Lawyers and Maurice Blackburn, plus key developments in separate, independently operated proceedings about the breach.

Investigation update July 2025

OAIC representative complaint — registrations accepted

Centennial Lawyers and Maurice Blackburn are involved in a representative complaint made to the OAIC concerning the 2022 Medibank data breach. Affected current and former Medibank Private and ahm customers are encouraged to register for updates about this complaint. Only a single contact method is required at this stage.

Regulatory action June 2024

OAIC files civil penalty proceedings against Medibank

The Office of the Australian Information Commissioner filed civil penalty proceedings against Medibank Private Limited in the Federal Court of Australia in June 2024. The OAIC alleges serious and repeated interferences with the privacy of approximately 9.7 million Australians in contravention of the Privacy Act 1988 (Cth). Penalties under the Privacy Act can be significant.

Law enforcement January 2024

Attacker identified and sanctioned by Australian, US and UK governments

In January 2024, the Australian Government — in coordination with the United States and United Kingdom — publicly identified and sanctioned Russian national Aleksandr Ermakov as the individual responsible for the Medibank cyberattack. This was the first time Australia had imposed a cyber sanction on an individual.

Court August 2023

Federal Court consolidates competing class actions

In August 2023 the Federal Court of Australia consolidated the competing class actions arising from the Medibank data breach into a single proceeding. This consolidated class action is separate from and independent of the OAIC representative complaint on this site — registering here does not join it.

Breach November 2022

Medibank confirms 9.7 million customers affected — data published on dark web

Medibank confirmed on 7 November 2022 that data belonging to 9.7 million current and former customers had been stolen. After Medibank refused to pay the ransom, the attacker began publishing stolen data on the dark web from 9 November 2022, including sensitive health records for approximately 480,000 customers.

MedibankDataBreach.com.au

Complaint information and registration

The primary public hub for the breach timeline, affected groups, and registration for updates on the OAIC representative complaint involving Centennial Lawyers and Maurice Blackburn.

ClassActions.com.au

Australian class actions registry

The wider registry of Australian class actions and legal investigations, maintained by ClassActions.com.au as the authoritative public resource.