The Termite ransomware gang has claimed responsibility for stealing sensitive healthcare data in a recent breach of Genea, one of Australia's largest fertility services providers. ... The redacted court order reveals that the threat actors breached Genea's network on January 31, 2025, through a Citrix server. Subsequently, they gained access to the company's primary file server, domain controller, backup program, and BabySentry primary patient management system. Two weeks later, on February 14, the attackers exfiltrated 940.7GB of data from Genea's compromised systems to a DigitalOcean cloud server under their control. The ongoing investigation also discovered that Genea's compromised patient management systems contained the following types of personal and health data, with the exposed information varying for each affected individual:
Full names, emails, addresses, phone numbers, date of birth, emergency contacts, and next of kin,
Medicare card numbers, private health insurance details, Defence DA numbers, medical record numbers, patient numbers,
Medical history, diagnoses and treatments, medications and prescriptions, patient health questionnaire, pathology and diagnostic test results, notes from doctors and specialists, appointment details, and schedules.
... While Genea didn't attribute the attack to a specific threat group or cybercrime operation, the Termite ransomware gang claimed responsibility on Monday. ...