Get all your news in one place.
100’s of premium titles.
One app.
Start reading
AAP
AAP
John Kidman

IVF hack inquiry confirms details published on dark web

An investigation has confirmed IVF provider Genea's patient management systems have been hacked. (Dean Lewins/AAP PHOTOS)

An IVF provider targeted in a cyber attack has written to patients confirming their stolen personal information has been posted on the dark net.

"The publication has occurred on a part of the dark web, which is a hidden part of the internet," according to Genea chief executive Tim Yeoh.

"This data is not readily searchable or accessible."

IV lab technicians at work
Genea has written to patients to advise them their personal information has been breached. (Dean Lewins/AAP PHOTOS)

An investigation following a security breach at the company on February 14 determined its patient management systems were accessed by an unauthorised third party or "threat actor".

The impacted servers were a store for a raft of personal information including full names, emails, addresses, phone numbers, Medicare card numbers, private health insurance details, medical history, diagnoses, treatments, medications and prescriptions.

The health data included clinical information related to services provided by Genea and other companies.

There was no evidence the hackers stole financial information such as credit card details or bank account numbers.

An international ransomware group published what it claimed was a sample of the confidential data after the attack forced Genea to shut down for several days.

The group claiming responsibility reportedly posted screenshots on dark net sites, boasting it had captured hundreds of gigabytes of patient data dating back more than five years.

General images of laboratory technicians at work
Genea's investigation confirmed the illegally obtained information was published on the dark web. (Dean Lewins/AAP PHOTOS)

Genea has not said how many customers have been impacted.

"We understand this news may be concerning for you," Mr Yeo wrote to customers.

"We unreservedly apologise for any distress that this may cause you."

He said Genea had undertaken a comprehensive analysis of the published stolen details to identify those impacted by the breach and the personal information relating to them.

The provider has been granted a court-ordered injunction to prevent anyone from accessing, using, disseminating or publishing any of the illegally obtained data. 

It has also partnered with national identity and cyber support service IDCare to guard against potential future lapses and to offer counselling to affected clients.

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.