NSW Health: Exclusive: NSW Health denies Medusalocker data breach claims

NSW Health: Exclusive: NSW Health denies Medusalocker data breach claims

MedusaLocker Claims Breach of NSW Health, But Government Denies Impact

On August 27, the ransomware group MedusaLocker listed NSW Health on its darknet leak site, alleging the theft of 103 emails and sensitive documents from the department. The threat actor shared a partial file tree containing folders labeled HR, Clients, Reports, and Marketing, with documents bearing letterheads from various medical and dental practices across New South Wales, particularly in the North Coast and Hunter regions.

Despite the claims, NSW Health has denied any breach of its systems, stating that its core network, applications, and data remain secure. A department spokesperson confirmed that no evidence of a cybersecurity incident has been found, adding that NSW Health continues to work with Cyber Security NSW and federal agencies to monitor and protect its infrastructure. The department also emphasized ongoing staff and vendor training to bolster cybersecurity awareness.

The leaked data spanning from 1999 to 2026 includes patient medical scans, Medicare numbers, addresses, and contact details, raising concerns that the breach may have originated from a third-party service provider rather than NSW Health itself. However, the identity of the potential third party remains unconfirmed.

MedusaLocker, first observed in 2021, is a relatively low-activity ransomware group with fewer than 100 known victims. After a period of inactivity, the group resurfaced in May 2026, listing 15 victims that month before ramping up operations again in July and August. While the group primarily targets entities in the U.S. and Germany, Australia has seen only two victims NSW Health and the Oscars Group, a hospitality firm breached in November 2025.

Source: https://www.cyberdaily.au/security/14131-exclusive-nsw-health-denies-medusalocker-data-breach-claims

NSW Health cybersecurity rating report: https://www.rankiteo.com/company/nsw-health

"id": "NSW1788323070",
"linkid": "nsw-health",
"type": "Ransomware",
"date": "8/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Patients of medical and dental '
                                              'practices in North Coast and '
                                              'Hunter regions',
                        'industry': 'Healthcare',
                        'location': 'New South Wales, Australia',
                        'name': 'NSW Health',
                        'type': 'Government Health Department'}],
 'attack_vector': 'Third-party service provider (alleged)',
 'data_breach': {'data_exfiltration': 'Yes (alleged)',
                 'file_types_exposed': ['Documents with letterheads',
                                        'Medical scans'],
                 'number_of_records_exposed': '103 emails and associated '
                                              'documents',
                 'personally_identifiable_information': 'Yes (Medicare '
                                                        'numbers, addresses, '
                                                        'contact details)',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, medical data)',
                 'type_of_data_compromised': ['Emails',
                                              'Medical scans',
                                              'Medicare numbers',
                                              'Addresses',
                                              'Contact details']},
 'date_detected': '2026-08-27',
 'date_publicly_disclosed': '2026-08-27',
 'description': 'On August 27, the ransomware group MedusaLocker listed NSW '
                'Health on its darknet leak site, alleging the theft of 103 '
                'emails and sensitive documents from the department. The '
                'threat actor shared a partial file tree containing folders '
                'labeled HR, Clients, Reports, and Marketing, with documents '
                'bearing letterheads from various medical and dental practices '
                'across New South Wales, particularly in the North Coast and '
                'Hunter regions. NSW Health denied any breach of its systems, '
                'stating its core network, applications, and data remain '
                'secure. The leaked data includes patient medical scans, '
                'Medicare numbers, addresses, and contact details, suggesting '
                'a possible third-party breach.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'alleged breach',
            'data_compromised': '103 emails and sensitive documents, including '
                                'patient medical scans, Medicare numbers, '
                                'addresses, and contact details',
            'identity_theft_risk': 'High (Medicare numbers, personal details '
                                   'exposed)'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain (ransomware)',
 'post_incident_analysis': {'corrective_actions': 'Enhanced monitoring, staff '
                                                  'and vendor training',
                            'root_causes': 'Possible third-party service '
                                           'provider breach (unconfirmed)'},
 'ransomware': {'data_exfiltration': 'Yes (alleged)',
                'ransomware_strain': 'MedusaLocker'},
 'references': [{'date_accessed': '2026-08-27',
                 'source': 'MedusaLocker darknet leak site'}],
 'response': {'communication_strategy': 'Public denial of breach, emphasis on '
                                        'ongoing cybersecurity efforts',
              'enhanced_monitoring': 'Yes (ongoing monitoring with Cyber '
                                     'Security NSW)',
              'incident_response_plan_activated': 'Yes (monitoring and '
                                                  'investigation)',
              'third_party_assistance': 'Cyber Security NSW, federal agencies'},
 'stakeholder_advisories': 'NSW Health advises stakeholders that no evidence '
                           'of a breach has been found in its core systems.',
 'threat_actor': 'MedusaLocker',
 'title': 'MedusaLocker Claims Breach of NSW Health',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.