Home/Incidents/Updoc

Updoc

6 Aug 2026 · National · Healthcare
Supply Chain Attack HIGH ✓ Verified

What happened

Australian telehealth provider Updoc issued formal security notifications to customers after identifying unauthorized access to an external third-party system supporting its operational workflows. Exfiltrated records were limited to account holder contact metadata, including customer names, email addresses, and postal locations across a platform serving over 1,000,000 users. Updoc confirmed its core internal infrastructure, medical records, consultation notes, and financial/payment systems remained uncompromised. Updoc blocked the access vector, instituted enhanced third-party API controls, and notified privacy regulators.

Incident details

Organisation
Updoc
Date
6 Aug 2026
Attack type
Supply Chain Attack
Severity
HIGH
Sector
Healthcare
State
National
Records affected
Unknown
Threat actor
Unknown

Source

7news.com.au ↗
← Back to all incidents