Security News > 2024 > January > US, UK, Australia sanction REvil hacker behind Medibank data breach
The Australian, US, and UK governments have announced sanctions for Aleksandr Gennadievich Ermakov, a Russian national considered responsible for the 2022 Medibank hack and a member of the REvil ransomware group.
Medibank is a large health insurance provider in Australia that suffered a ransomware attack in October 2022, causing operational and business disruption.
Following a lengthy investigation, the Australian authorities identified Ermakov as the person responsible for the Medibank hack and data theft.
The United States and United Kingdom also announced sanctions against Ermakov in a coordinated announcement with Australia.
In a press conference at Canberra, Australia's Home Affairs and Cyber Security Minister confirmed that Ermakov was a member of the REvil ransomware operation and he was not among the individuals that Russia detained in early 2022 under suspicion of being members of the REvil group.
As the sanctions in response to the Medibank Private cyber incident have a financial component, this means that whoever provides assets to Ermakov, including cryptocurrency or ransomware payments, would be committing an offense.
News URL
Related news
- Fortinet confirms data breach after hacker claims to steal 440GB of files (source)
- Dell investigates data breach claims after hacker leaks employee info (source)
- US, UK warn of Russian APT29 hackers targeting Zimbra, TeamCity servers (source)
- USDoD hacker behind National Public Data breach arrested in Brazil (source)
- Cyber crooks shut down UK, US schools, thousands of kids affected (source)
- 23andMe to pay $30 million in genetics data breach settlement (source)
- AT&T pays $13 million FCC settlement over 2023 data breach (source)
- Temu denies breach after hacker claims theft of 87 million data records (source)
- Hackers Exploit Default Credentials in FOUNDATION Software to Breach Construction Firms (source)
- Disney ditching Slack after massive July data breach (source)