GO2 Health Hit by Business Email Compromise Attack, Exposing Patient Data
GO2 Health, a Brisbane-based medical provider serving over 14,000 patients including 7,000 veterans confirmed it fell victim to a business email compromise (BEC) phishing attack, leading to unauthorized access of patient data. The incident was first reported by the ABC on 21 July, though GO2 Health detected the breach on 24 April after identifying suspicious activity in one of its email mailboxes.
The attack targeted a single mailbox, which contained limited patient data, including Department of Veterans Affairs ID numbers. While the compromised inbox used an auto-archive system, restricting exposure to emails from the 12 months prior to the incident, GO2 Health confirmed no evidence suggests the data was published or misused. The organization’s primary patient information storage system remained unaffected.
Following the breach, GO2 Health engaged external cybersecurity experts to investigate and contain the incident. It also notified affected individuals, the Australian Cyber Security Centre (ACSC), and the Office of the Australian Information Commissioner (OAIC), providing ongoing updates to regulators. The investigation, described as complex, took time to ensure accurate identification of impacted patients and avoid misinformation.
No threat actor has been identified, and GO2 Health has not disclosed further details on the attack’s origin. The organization, which operates general practice and veteran care services under its REFORGE clinic, emphasized its commitment to patient privacy while addressing concerns about the incident’s handling.
Go2Health! cybersecurity rating report: https://www.rankiteo.com/company/go2health
"id": "GO21784708766",
"linkid": "go2health",
"type": "Breach",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '14,000 patients (including '
'7,000 veterans)',
'industry': 'Healthcare',
'location': 'Brisbane, Australia',
'name': 'GO2 Health',
'type': 'Medical Provider'}],
'attack_vector': 'Phishing',
'customer_advisories': 'Notified affected individuals',
'data_breach': {'data_exfiltration': 'No evidence of data being published or '
'misused',
'personally_identifiable_information': 'Department of '
'Veterans Affairs ID '
'numbers',
'sensitivity_of_data': 'High (medical and personal '
'identifiers)',
'type_of_data_compromised': 'Patient data, Department of '
'Veterans Affairs ID numbers'},
'date_detected': '2024-04-24',
'date_publicly_disclosed': '2024-07-21',
'description': 'GO2 Health, a Brisbane-based medical provider, fell victim to '
'a business email compromise (BEC) phishing attack, leading to '
'unauthorized access of patient data. The attack targeted a '
'single mailbox containing limited patient data, including '
'Department of Veterans Affairs ID numbers.',
'impact': {'data_compromised': 'Department of Veterans Affairs ID numbers, '
'patient data from emails in the compromised '
'mailbox',
'identity_theft_risk': 'Potential',
'systems_affected': 'Single email mailbox'},
'investigation_status': 'Ongoing (complex investigation to ensure accurate '
'identification of impacted patients)',
'references': [{'date_accessed': '2024-07-21', 'source': 'ABC'}],
'regulatory_compliance': {'regulatory_notifications': ['Australian Cyber '
'Security Centre '
'(ACSC)',
'Office of the '
'Australian '
'Information '
'Commissioner (OAIC)']},
'response': {'communication_strategy': 'Notified affected individuals, '
'regulators, and provided ongoing '
'updates',
'containment_measures': 'Engaged external cybersecurity experts '
'to investigate and contain the incident',
'incident_response_plan_activated': True,
'third_party_assistance': 'External cybersecurity experts'},
'title': 'GO2 Health Business Email Compromise Attack',
'type': 'Business Email Compromise (BEC)'}