Threat actors used stolen high-level credentials from a third-party IT service provider to gain access to Medibank's corporate network. The attackers exfiltrated highly sensitive customer data, including full names, dates of birth, Medicare numbers, and private medical diagnosis codes, before posting the data to a dark web leak site.