Lack of Multi-Factor Authentication

...

In October 2022, Medibank, one of Australia's largest health insurers, suffered a major data breach that exposed the personal and health information of approximately 9.7 million current and former customers. The attack began when cybercriminals gained access to a Medibank IT service desk operator’s login credentials. These credentials had been synchronized to the employee’s personal device, which was infected with malware, allowing attackers to steal them.

The attackers then accessed Medibank’s internal systems via the company’s Virtual Private Network (VPN). Critically, the VPN only required a username and password, with no Multi-Factor Authentication (MFA) in place. Over the course of nearly two months, the attackers exfiltrated 520GB of sensitive customer data, including names, dates of birth, Medicare numbers, and health claims data. The stolen information was later leaked on the dark web after Medibank refused to pay the ransom.

The Medibank attack demonstrates the catastrophic risks of failing to enforce MFA. A single compromised credential led to a massive data breach, highlighting the necessity of multi-layered security in access control.

Medibank had previously been advised to implement MFA following security reviews in 2020 and 2021, but these recommendations were not enforced. Additionally, security alerts indicating unusual activity were not properly escalated, allowing the attackers to maintain prolonged access to the system.

Following the breach, Medibank strengthened its security by enforcing MFA across all remote access systems, increasing security monitoring, and improving incident response protocols. This case serves as a stark reminder that even basic security measures like MFA can prevent devastating breaches. Organizations must proactively implement recommended security controls, conduct regular audits, and ensure security alerts are thoroughly investigated to mitigate risks.