Medibank’s failure to require its workers to use multi-factor authentication is what allowed hackers to obtain the personal information of its customers, the Australian privacy regulator alleges in new court documents.
The hack on Medibank resulted in the personal details of 9.7 million current and former customers – including 5.1 million Medibank customers, 2.8 million ahm customers and 1.8 million international customers – being published on the dark web.