Modern Australian
Times Advertising

We still don’t know the extent of the MediSecure breach, but watch out for these potential scams

  • Written by Paul Haskell-Dowland, Professor of Cyber Security Practice, Edith Cowan University
We still don’t know the extent of the MediSecure breach, but watch out for these potential scams

On Thursday last week, Australian media began reporting that an unnamed “commercial health information organisation” had been targeted by cyber criminals.

Within hours, reports quickly confirmed that data relating to digital prescriptions for Australian patients had been caught up in a ransomware incident at the Melbourne-based MediSecure.

The public may be concerned at the lack of information shared to date, with the Australian government still saying it is in the preliminary stages of its response, and investigations are ongoing.

It is quite normal for such investigations to take time. In fact, it’s likely to be several days (even weeks) before we have a full picture of the impact.

While these investigations progress, it is important to be alert to opportunistic scams that are likely to emerge in the coming days – even if you have never received a digital prescription.

Am I a victim of the MediSecure breach?

MediSecure provided digital prescription (eScript) services across Australia until late 2023. The company would have held personal details and some limited medical data relating to prescriptions.

If you received a prescription (via email or SMS) prior to November, it is possible your medical practice was using the MediSecure prescription system. You can potentially check this by consulting older scripts and seeing if the hyperlink was issued via MediSecure.

However, there is currently no information that would allow us to determine who is affected. For many, this will be disappointing as there would obviously be records that would indicate which healthcare practices were using the prescription service from MediSecure.

It is, however, possible this data is currently inaccessible due to the ransomware incident. Alternatively, the government may be working with providers to plan communications with those who are affected. This could be a good way to manage the sharing of information with these people, if handled in a timely fashion.

What about more recent prescriptions?

From November 15 2023, MediSecure ceased processing prescriptions in Australia after a tender process allocated the contract to a single company, eRx. Almost 190 million digital prescriptions were issued in the last four years between the two providers.

The government has provided assurance that services provided by eRx have not been affected:

People should keep accessing their medications and filling their prescriptions. This includes prescriptions (paper and electronic) that may have been issued up until November 2023.

Close-up of a medicare card in a black leather wallet with numbers partially obscured.
The government is assuring people that Medicare card details alone can’t be used as identifying information. AAP Image/Dave Hunt

Look out for potential scams

The priority at the moment is to determine the level of the breach. Investigations will reveal if the company has simply been locked out of its systems, or if data was also stolen.

Meanwhile, there is potential for scams to start appearing – including ones that originate from completely unrelated criminal groups.

Criminals won’t miss an opportunity to capitalise on a public interest story, including significant events. Following the Optus data breach, it did not take long before criminals were establishing new campaigns to manipulate the public in the wake of a major security issue.

It is highly likely we will soon see scams that use the MediSecure story as a “hook”. This could be as simple as providing a link to “find out if you are a victim” or even offering to help alleged victims reclaim their data and/or identity.

If, however, the criminals behind the MediSecure ransomware have taken the data for their own use, we are potentially facing much bigger issues.

With access to personal information, prescription data and (possibly) a person’s Medicare card number, scammers can add an air of authenticity to their campaigns.Imagine receiving an official-looking email that includes the final four digits of your Medicare card to “verify” the email is genuine. The email might even assure you it is genuine by saying it has not included the full number for “your security”.

If stolen data is then released (likely on the dark web), there is potential for other criminals to use the data in campaigns. This recently happened following the Optus data breach.

What next?

The investigation will be continuing for the coming weeks. The primary aim is to determine how much data has been accessed, if it has been copied and how many people are affected.

So far, we have been assured no identity documentation is at risk, as Medicare records contain limited information that would not allow for identity theft.

The most important message at the moment is to be alert. We are likely to see scams emerging over the coming days that will leverage this incident. Many will likely be very convincing.

If you receive direct communications claiming to be from MediSecure, stop. Refer to the Home Affairs website which will be updated with the latest information.

The Australian Competition and Consumer Commission’s Little Black Book of Scams is a great reference to raise awareness of the techniques used by cyber criminals.

Authors: Paul Haskell-Dowland, Professor of Cyber Security Practice, Edith Cowan University

Read more https://theconversation.com/we-still-dont-know-the-extent-of-the-medisecure-breach-but-watch-out-for-these-potential-scams-230402

Why I/O Controller Is Essential For Efficient Industrial Automation Systems

Modern industrial systems rely heavily on automation and precise data exchange, which is why an I/O controller plays a critical role in ensuring sm...

Why Modern Traffic Management Systems Are Important For Safer Roads

Cities and industrial facilities increasingly rely on advanced Traffic Light System technology to improve road safety, traffic flow, and operationa...

How Structured eCommerce Web Design Influences Online Buying Behaviour

A strong online presence begins with effective eCommerce web design that prioritises both functionality and user experience. Businesses entering or...

What People Mean by “Alternative Doctor” And Why Expectations Around Care Are Changing

When people search for an “alternative doctor,” they’re usually looking for something specific, even if they haven’t fully defined it yet. I...

Why Does My Power Keep Tripping? Common Causes Explained by Electricians Sydney

The electrical system is the lifeblood of your home, powering everything from your phones to cooking utensils and more. But from time to time, your po...

Interstate Car Transporter Urges Buyers to Book Early

As the conflict in the Middle East continues to put increasing pressure on local fuel supply, Australian transport companies are experiencing increasi...

Digital Minimalism for Business Owners: Fewer Tools, Better Systems

Be honest. How many apps are open right now? One for scheduling, another for invoices, a third for customer notes, plus a spreadsheet someone email...

The Importance Of Proactive NDIS Renewal Preparation For Sustaining Your Provider Business

Your NDIS renewal notice is not a signal to start preparing. By the time it arrives, preparation should already be well underway. For new providers, s...

Why Fire Extinguisher Testing in Sydney Is Becoming a Records Game, Not Only a Maintenance Job

A fire extinguisher used to feel like one of the simpler parts of building safety. It hung on the wall, wore a service tag, and sat there quietly unle...

The Switchboard Upgrade Question Every Melbourne Renovator Should Ask Before the Walls Close Up

Renovations have a funny way of making people think on surfaces first. Splashback, stone, joinery, tapware, paint. Fair enough too. That is the exciti...

Winter Sanitation Gaps in Parramatta Kitchens: A Hidden Pest Risk

Winter brings a host of changes to our homes, from the chill in the air to the cozy warmth indoors. However, this season also introduces sanitation ch...

When to Seek Advice from Employment Lawyers in Melbourne

Australian employment law is detailed and, at times, complex, with rights and obligations that aren't always obvious to employees or employers witho...

7 Benefits of Professional Gutter Cleaning for Australian Homeowners

Gutters aren't exactly glamorous. They sit up there on the edge of your roof, doing their job quietly - until they stop working. Clogged, overflowing ...

Pipe Floats Strengthening Pipeline Performance In Demanding Environments

Pipelines often travel through environments that are anything but predictable, water currents shift, terrain changes, and materials keep moving unde...

Why Ceiling Fans Are Essential For Comfort, Efficiency, And Modern Living

Creating a comfortable indoor environment is not just about temperature; it is about how air moves, how a room feels, and how efficiently energy is ...

Why Duct Cleaning In Melbourne Is A Smart Investment For Healthier Living Spaces

Behind your walls, ceilings, and vents lies a network quietly working every day to keep your home comfortable. Yet over time, this system can become...

Disability Service Providers Supporting Inclusive And Independent Living

Finding the right support system can feel like assembling a puzzle where every piece must fit just right. For individuals and families navigating di...

A Beginner's Guide to Owning a Caravan in Australia

Owning a caravan opens up a style of travel that's hard to match for freedom and flexibility. However, for those just starting out, the process of c...