Medusa ransomware group claims data from Sydney's Crown Princess Mary Cancer Centre
- Organization
- Crown Princess Mary Cancer Centre
- Exploit
- Ransomware
- Industry
- Healthcare
In early May 2023 the Medusa extortion group added the Crown Princess Mary Cancer Centre, part of Westmead Hospital in Sydney, to its dark web leak site. The listing appeared around May 4 and carried a seven-day countdown before the group said it would publish material it claimed to have taken.
Medusa set tiered demands, offering to delay publication by 24 hours for about US$10,000 or to download and delete the data for US$100,000. The group said it held thousands of files and posted a file listing plus sample images as proof, some of which were reported to contain identifiable patient information.
NSW Health said the incident did not appear to have impacted any NSW Health databases or the cancer centre's own databases, and that the security of its systems was continually monitored. Neither the centre nor the health department confirmed how much data had been taken or what categories it covered, and the claim rested on the attackers' own postings.
The case drew wide comment in Australia because it followed the Medibank and Optus breaches and fed into the debate over whether ransom payments should be banned outright. Analysts noted that Medusa had claimed at least 20 victims since January 2023 and had become one of the more active extortion groups operating in the region.