Earlier, Medibank chief executive David Koczkar sent a clear message to the criminals who hacked the records of 9.7 million customers, insisting the insurer was not going to change its decision to reject the $US10 million ($15 million) ransom demand.
Loading
“There is no doubt that rejecting the ransom demand was the right thing to do,” Koczkar told investors at the private health insurer’s annual meeting on Wednesday morning.
Earlier this week, the criminals declared that no further information would be released until Friday, indicating they would be watching the shareholder meeting with interest.
“There is some more records for everybody to know,” they wrote in a blog update.
“We’ll announce, that next portion of data we’ll publish at Friday, bypassing this week completely in a hope something meaningful happened on Wednesday.”
Koczkar said the company’s resolve had not diminished in the wake of the steady leak of sensitive customer data.
“While we unreservedly apologise for the impact of the release of the data, we cannot as a community, pay criminals who are likely to continue to extort us all – particularly when there is no guarantee that the criminal would ever delete the data. As I’ve said before, you cannot trust a criminal.”
Medibank CEO David Koczkar said the company’s resolve to not pay the hackers had not changed. Credit:AFR
Koczkar also warned that customers and media should not take the material published by hackers as fact.
“This is a complicated process. The data that’s actually on the dark web is sometimes not accurate. It’s not complete,” he said.
“We need to make sure we match the data back to the data in our systems to make sure that we communicate very clearly.”
He reiterated that Medibank’s current response to the crisis would incur costs of up to $35 million for the December half. This does not include further potential customer and other remediation, regulatory or litigation-related costs.
Wilkins apologised to investors and customers in his speech.
“It has caused distress and concern for many of our customers, our people and for you, our shareholders – many of whom I know are also customers,” he said.
“I unreservedly apologise to every person for the significant impact of this crime. It is a despicable act by the criminal seeking to extort payment based on the privacy concerns of our customers and must be condemned in the strongest possible terms.”
Wilkins said the board would continue to invest in mitigating these risks and indicated that major shareholders and advisers had shown support for the board ahead of what was expected to be a fiery meeting with shareholders able to question the board members and executives about the attack.
The data was stolen by hackers in October. Medibank revealed last week it had rejected hacker demands that it pay a ransom in return for it not being released. The ransomware group suspected to be behind the attack then began releasing tranches of stolen Medibank data on the dark web.
Proxy advisers have warned that Medibank Private’s executives and board will be held accountable for the catastrophic cyberattack which exposed customers, but the private health insurer’s top managers won’t be facing a strike against its remuneration report today.
Proxy investment advisers ISS and CGI Glass Lewis are telling investors to support all resolutions at the meeting, including the remuneration report and performance incentives for Koczkar. He received more than $2 million worth of short-term incentives and performance rights as part of his remuneration of $3.76 million last year.
Shareholders appeared to agree. Medibank released details of proxy votes ahead of final voting on the resolutions and it showed overwhelming support for all items on the agenda.
However, while CGI Glass Lewis has recommended all directors be re-elected on Wednesday to ensure the group has a stable board to respond to “rapid developments”, it flagged board renewal and executive scalps may be needed over the coming year and raised the spectre of executive pay “clawbacks” to account for any shortcomings that allowed the attack to be so damaging.
The hacking incident escalated again on Monday when this masthead revealed that employee data was also hacked, potentially opening up new vulnerabilities for Medibank’s computer systems.
The theft was part of the same hack that acquired data on all 9.7 million current and former customers, including sensitive health information on about 500,000 policyholders.
Loading
The Australian Federal Police are stepping up efforts to contain the fallout of the hack amid emerging evidence that the sensitive health data leaked by the criminals is becoming more publicly available.
“The Australian Federal Police are aware of data on new sites and will be addressing it,” a Medibank Private spokeswoman said in response to inquiries.
The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.









Add Category