Medibank detected unusual activity on its network on 12 October 2022 and told the Australian Securities Exchange the following day, which puts the discovery date a day ahead of the disclosure date and the intrusion itself considerably older than either. What it did first was defensive and sensible. It took the ahm and international student policy management systems offline, requested a trading halt, and rebuilt them on new infrastructure, telling the market that normal activity had resumed for that business on Friday 14 October. What it also said, in the same statement, was that there was no evidence any sensitive customer data had been accessed. It repeated that assurance on 17 October, by which point the activity had already been characterised as consistent with the precursors to a ransomware event.

The correction did not come from Medibank's own forensics. On 19 October the company received messages from someone who wanted to negotiate and supplied, as proof, a sample covering 100 policies — names, addresses, dates of birth, Medicare numbers, telephone numbers and medical claims data. Medibank confirmed the next day that the sample was genuine and had come from the ahm and international student systems. From there the concession widened almost daily. On 25 October the company said the criminal had taken Medibank customer data as well as ahm and international student data; on 26 October it said it believed the criminal had accessed all ahm customers' personal data and significant amounts of health claims data, and all international student and Medibank customers' data on the same terms.

How the attacker got in was not set out publicly until much later, and the fullest account is the Australian Information Commissioner's, filed in the Federal Court in June 2024 — an allegation tested in litigation rather than a forensic report published by the company. On that account, an employee of a Medibank IT contractor saved his work credentials in a browser signed in on his personal computer; malware installed on that machine in August 2022 harvested them, including an administrator account with broad reach. The corporate VPN did not require multi-factor authentication, so a device certificate or a password was sufficient. Roughly 520 gigabytes were taken out between late August and 13 October. The intrusion had been running for about two months before anyone noticed anything at all.

What distinguished this from the Optus breach three weeks earlier was the file itself. Health claims data does not describe who a person is; it describes what was done to them, on what date, by which provider. Medibank's public refusal to pay, the attackers' decision to publish in curated batches sorted by condition, and the counting that produced the figure of 9.7 million customers all belong to November, and are covered in the next edition of this archive. October's contribution is narrower and, in the long run, more instructive: a fortnight in which a listed company told its market and its customers there was no evidence of a problem, while someone else sat on half a terabyte of their medical histories and waited to be taken seriously.

Also that month · Back to paper

A hospital chain lost its records

CommonSpirit Health, then one of the largest non-profit hospital systems in the United States, detected malicious activity on 2 October 2022 and acknowledged an IT security incident publicly within days, but declined throughout October to say whether ransomware was involved — the confirmation that it had been came only with the breach notice it published in December 2022. The unauthorised access, as later reconstructed, ran from 16 September to 3 October — an intrusion window that had closed the day after detection began. The effect was immediate and physical: electronic health records were taken offline as a precaution across facilities in Nebraska, Tennessee, Texas, Washington and Iowa, and the Virginia Mason Franciscan Health hospitals in Washington state rescheduled surgeries and appointments while clinicians worked on paper. Most sites recovered within two to three weeks; a handful still did not have every system restored on 9 November. CommonSpirit notified 623,774 individuals in December 2022 and confirmed in April 2023 that 164 facilities had been affected. The figure it eventually reported, about $160 million after an upward revision from $150 million in May 2023, covered business interruption, remediation and related expenses — a total incident cost, not lost revenue.

Also that month · Claim and confirmation

Microsoft confirmed the hole, not the number

On 19 October 2022 the threat intelligence firm SOCRadar published research it branded BlueBleed, describing a misconfigured Microsoft storage endpoint it said it had detected on 24 September and reported to the company. SOCRadar's claim was 2.4 terabytes of business data — invoices, product orders, signed customer documents, partner ecosystem records — touching more than 65,000 entities across 111 countries, in files dated between 2017 and August 2022. Microsoft published its own note the same day, and the two halves of it are worth separating carefully. It confirmed the misconfiguration, said the endpoint had been secured after SOCRadar's report, and described the exposed fields as including names, email addresses, email content, company names and telephone numbers. It then said SOCRadar had greatly exaggerated the scope, that its own analysis of the data set found duplicate references to the same emails, projects and users, and it objected publicly to the searchable lookup tool SOCRadar had built, which the firm suspended that day. Microsoft published no figure of its own. The only number in circulation was therefore the researchers', and it has never been independently confirmed.

India desk · October 2022

Tata Power, and the eleven-day gap

Tata Power, India's largest integrated power company, told the stock exchanges on 14 October 2022 that it had suffered a cyber attack on its IT infrastructure affecting some of its IT systems. The filing was short and carefully bounded. It said the company had taken steps to retrieve and restore the systems, that all critical operational systems were functioning, and that restricted access and preventive checks had been placed on employee and customer-facing portals as a measure of abundant precaution. It did not name an attacker. It did not say that any data had been taken. Ten days later, on 24 October, the Hive ransomware operation listed Tata Power on its leak site and began publishing files, claiming it had encrypted the company on 3 October — eleven days before the exchange filing.

What Hive published was described by researchers who examined it as employee records including Aadhaar numbers, PAN details, salary information, addresses and telephone numbers, alongside engineering drawings, financial and banking records and client information. Those descriptions come from the gang's own leak-site postings and from analysts who downloaded them. Tata Power has never confirmed a data theft, and the 3 October encryption date is the attackers' assertion, not a published forensic finding. The gap it implies matters more in India than elsewhere, because CERT-In's April 2022 direction has required covered entities to report specified incidents within six hours of noticing them since 27 June 2022. Whether Tata Power met that deadline is not a matter of public record and cannot be, since reports made to CERT-In are not published. The regime creates a duty that the public has no way of watching being discharged.

AI Tech desk · October 2022

Two unicorns, six weeks before ChatGPT

Generative AI spent October 2022 being priced. On 17 October 2022 Stability AI, the London company behind Stable Diffusion, announced a $101 million raise led by Coatue and Lightspeed at a reported valuation of about $1 billion; a day later Jasper, an Austin firm selling GPT-3-written marketing copy, raised $125 million at $1.5 billion. On 25 October Shutterstock said it would sell imagery generated by OpenAI's DALL-E 2 and pay into a fund for the contributors whose images had trained it, choosing licensing where Getty, weeks earlier, had chosen a ban. Google's researchers opened the month with Imagen Video, extending diffusion models from still images to moving ones. ChatGPT was six weeks away, and it rearranged all of this: Jasper spent the years since repositioning around a capability its customers could suddenly get free; Stability never matched that valuation again, lost its founder in 2024 and needed recapitalising; and Shutterstock agreed in 2025 to merge with Getty after all.

Digital Guard desk · October 2022

Endpoint security becomes someone else's job

The trade that sells protection had a quieter October than its customers, and spent it pivoting to services. On 12 October 2022 Malwarebytes launched a managed detection and response service, putting its own analysts behind the endpoint agents it sells to smaller organisations — an admission, general across the industry by then, that products were generating more alerts than their buyers had staff to read. The same week, at its Ignite conference, Microsoft retired the Endpoint Manager brand and folded device management back into Intune, a tidying exercise by the vendor whose Defender ships inside every Windows machine by default. And on 26 October Cybereason, the Boston endpoint security firm that had been weighing a multi-billion-dollar flotation a year earlier, confirmed its second round of cuts of the year — about 200 jobs, roughly 17 per cent of its staff. The retrenchment held: Cybereason passed into SoftBank's control the following spring, agreed a merger with Trustwave in 2024, called it off, and took further rescue funding in 2025.

⏳ Time capsule — October 2022

  • NASA confirmed on 11 October that its DART spacecraft had shortened the orbit of the asteroid moon Dimorphos by 32 minutes, against a success threshold of 73 seconds.
  • Liz Truss announced her resignation on 20 October, ending the shortest premiership in British history; Rishi Sunak took office on 25 October.
  • Taylor Swift released Midnights on 21 October, setting Spotify records for the most-streamed album in a single day and the most-streamed artist in a single day.
  • Elon Musk completed his $44 billion acquisition of Twitter on 27 October and dismissed the chief executive, chief financial officer and senior legal staff the same day.
Where it stands today — 2026

Still before the court

Medibank's October has outlasted almost everything else in this archive's 2022 volume. Australia sanctioned the Russian national Aleksandr Ermakov over the breach in January 2024, the first use of its cyber sanctions powers, with the United States and United Kingdom acting alongside it. The Information Commissioner filed civil penalty proceedings in the Federal Court on 5 June 2024, alleging that from March 2021 to October 2022 the company failed to take reasonable steps to protect the personal information of 9.7 million Australians. Those proceedings were still on foot in 2026, the regulator referring to them alongside its Optus case in March of that year. The technical failing at the centre has never grown more sophisticated in the retelling: a VPN that did not ask for a second factor.

The other threads close more tidily. On 28 November 2022, with the stolen files still being posted in batches, Australia's Parliament passed the Privacy Legislation Amendment (Enforcement and Other Measures) Act, raising the maximum penalty for serious or repeated interference with privacy to the greater of A$50 million, three times any benefit obtained, or 30 per cent of adjusted turnover; it came into force on 13 December. And Hive, which spent October's last week publishing Tata Power's files, did not see out the winter. The FBI has since said it held covert access inside the gang's networks from late July 2022, which means those posts went up while investigators were already inside and unable to stop them. The takedown came on 26 January 2023, and this archive covers it.