Genea discloses breach after Termite ransomware attack on IVF clinics

Organization
Genea
Exploit
Ransomware
Industry
Healthcare

Genea, one of Australia's largest fertility providers, told patients in February 2025 that it had detected suspicious activity on its network and that an unauthorised third party had accessed its systems. The company took servers offline as a precaution, and patients reported that phone lines and the MyGenea app were unavailable.

The Termite extortion group claimed the attack days later and listed Genea on its darknet leak site, saying it held around 700GB of data. BleepingComputer reported that the intruders first entered the network through a Citrix server on 31 January 2025 and moved data to a DigitalOcean cloud server on 14 February. Genea's court filing puts the volume exfiltrated at 940.7GB.

Genea said the affected records could include patient names, contact details, dates of birth, Medicare card numbers, private health insurance details, medical histories, diagnoses, treatments, medications and test results. The company said there was no evidence that credit card details or bank account numbers had been affected.

Genea obtained a court injunction restraining further sharing of the stolen files and said it was engaging with the Office of the Australian Information Commissioner, the Australian Federal Police, the National Cyber Security Coordinator and the Australian Cyber Security Centre. Cyber Daily reported on 5 March that Termite had published further stolen data on the dark web despite the injunction, and that Genea had confirmed the additional release.

Sources