Is your practice a cyber target?

7 minute read


Cybercrime cost Australians $2.2 billion last year. Healthcare was hit harder than any other sector.


With 95% of cyberattacks on healthcare succeeding last year, according to the Australian Signals Directorate’s Annual Cyber Threat Report 2024-2025, GPs and practice staff can no longer trust their existing IT setup. 

Speaking at NAB Health’s Cyber Security Awareness Webinar for the healthcare sector this week, Laura Hartley – a cybersecurity criminologist and head of NAB’s Group Security team – said the healthcare sector remained the most targeted industry in Australia for data breaches. 

This year has already seen several major healthcare data breaches.  

 Manage My Health was hacked in January, with criminals gaining access to medical documents and personal information for roughly 125,000 of its 1.8 million users.  

In March, Stryker Corporation was hit by a politically motivated cyberattack, attributed to an Iran-linked hacktivist group, that wiped out 200,000 devices globally and destroyed 50 terabytes of data.   

In June, confidential patient records from 21 Partnered Health GP clinics were held for ransom, and in July a separate breach of telehealth platform Updoc compromised patient contact details.  

Malicious actors succeeded in 95% of cyberattacks against healthcare, compared with 52% across other industries, according to the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC).  

“Healthcare continues to be a real target for criminals due to the vast amount of information you hold on patients and the fact that much of it is sensitive,” Ms Hartley said. 

The average net loss from scams has continued to climb, from roughly $100,000 for medium-sized businesses to $200,000 for larger ones, Ms Hartley said.  

“Losing that amount of money, a lot of businesses would simply go out of business,” she told the webinar.  

Human error, such as falling for phishing scams or using weak passwords, accounted for approximately 20% of healthcare data breaches. 

Ransomware attacks on the sector also doubled in the last financial year

Non-hospital clinical providers are targeted by almost 10 times as many attacks as hospitals, according to CyberCX – increasingly through business email compromise.  

Real-time voice and video cloning, AI-generated phishing emails and deepfakes are making scams appear more convincing than human-generated ones, though impersonation itself is not yet widespread, Ms Hartley said.  

Investment scams, often involving the impersonation of legitimate banks and financial institutions, remain the largest driver of financial fraud losses nationally, routinely causing more damage than all other major scam categories combined. 

Attackers are also now using AI to hunt for software vulnerabilities.  

“AI is now going looking for vulnerabilities on the internet, which is fantastic for trying to close holes, but also means that criminals are trying to exploit them,” she said.  

Sticking to the basics 

Despite cybercrime’s growing sophistication, Ms Hartley said the fundamentals of protection remain the same. 

The first step is to verify any requests for money or bank details independently, either by calling your banker directly or by calling the phone number listed in your bank’s app, rather than any number supplied in a message.  

Phishing emails typically carry small tells, such as being sent from an address that isn’t the organisation’s genuine one, but they always create a sense of urgency or request personal information, Ms Hartley said.  

SMS phishing increasingly uses non-clickable links, making them harder to detect and block, she told the webinar.  

If an employee requests a change to their bank account details by phone or email, verify the request in person or by calling the number already on file in the HR system, as emails can be compromised. 

Real email threads can be compromised by hackers, who then send a follow-up email claiming that there has been a change to bank account details.  

Ms Hartley said not to rely on any phone number provided in the message. Instead, call a banker directly or search for the publicly listed number online.   

Once a payment is made to a fraudster’s bank account, it is typically funnelled into smaller payments, cashed out at ATMs or passed on to money mules, making it harder to recover.  

“If we can’t recover the money, that loss will usually sit with the business itself that authorised the payment,” the cybercrime expert said.  

Criminals tend to be either opportunistic, using so-called “spray and pray” attacks, or targeted, using media coverage of merger or acquisition announcements, or by exploiting new starters, who were often most vulnerable within their first 60 to 90 days. 

Ms Hartley said it was also important to empower staff, particularly newer or junior employees, to flag anything that appears inconsistent.  

“Talk about [scams] regularly through the course of your working week, so that if you receive [a phishing email or invoice scam] like this, it’s not the first time that you’re having that conversation, and that people know exactly how you want it to be handled,” she said. 

Ransomware and back ups  

“Malware is malicious software or a computer virus, and ransomware locks or encrypts all the files on your computer or your devices and makes them inaccessible until someone pays the ransom,” Ms Hartley said.  

Ransomware often uses military-grade encryption, and even paying the ransom does not guarantee regaining access to the data, she said.  

Backing up data in the cloud or physically offsite is essential, including regular backups and testing to ensure reliability.  

“Practice restoring from your backup so that you know you’ll be able to rely on them if you ever need them,” she said.  

Activating automatic updates is also essential in preventing malicious software.  

Information and highly personalised documents taken from previous data breaches have also been used to attempt to open bank accounts, which are then used to move money obtained from the scams, she said. 

Ms Hartley advised larger businesses not to rely on standard internet banking, saying it lacks the payment controls built into business banking platforms such as NAB Connect. 

“It’s not that internet banking isn’t secure. It absolutely is. It’s just that the payment controls around it aren’t designed for a business because it’s designed for personal bank customers,” she said.  

Other essentials include using separate passwords for each application, enabling multi-factor authentication, not saving passwords in browsers such as Chrome or Safari, and not granting all staff administrative privileges on work devices.  

Password manager apps, including LastPass and Dashlane, use an encrypted vault to store unique, complex passwords for each account.  

Even if the vault itself is compromised, Ms Hartley said, criminals can only see the encrypted versions, which are effectively useless to them.  

End of content

No more pages to load

Log In Register ×