Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
Australian IVF provider, Genea, was attacked by the Termite ransomware group with attackers, allegedly, stealing 700 GB of highly sensitive patient and publishing it on the dark web. This included highly personal and confidential information of Genea's IVF patients, such as medical histories, Medicare numbers, passport data, contact details, and test results.
The attack caused significant disruption to Genea's operations, with phone lines going down and the MyGenea app becoming inaccessible, leading to patient anxiety and frustration. The breach was detected on February 14, 2025, after suspicious activity was observed on the network, but the impact quickly escalated as patients struggled to contact clinics for urgent medical inquiries and treatment plan updates.
We’ve captured everything that took place in this major healthcare data breach in our Genea Cyber Attack Timeline and Visual Summary Image.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
In February 2025, Genea — one of Australia's largest IVF and fertility providers — confirmed it had been hit by a cyber attack after an unauthorised third party accessed its network. The incident, reportedly carried out by the Termite ransomware group, disrupted Genea's phone lines and the MyGenea patient app, and led to a large volume of sensitive patient data — reportedly more than 700 GB — being stolen and later published on the dark web. Genea notified Australian regulators, obtained a court-ordered injunction to limit the spread of the leaked data, and engaged cybersecurity partners and law enforcement. Because the stolen information included highly sensitive medical, fertility and identity records, it became one of the most serious healthcare data breaches in Australia in 2025.
Genea became aware of suspicious activity on its network on 14 February 2025, the same day its phone lines went down. A court order later cited in reporting indicated the attackers had been inside Genea's network from around 31 January 2025 — more than two weeks before detection — and had extracted data on 14 February. Genea publicly confirmed the cyber incident on 19 February 2025, the threat actor began publishing stolen data around 26 February, the Australian Passport Office responded on 28 February, and Genea confirmed that further data had been leaked on 4 March 2025.
The attack was reportedly carried out by the Termite ransomware group, which claimed responsibility and posted samples of stolen data on its dark web leak site. The attribution was reported by threat-intelligence sources such as HackManac and covered by outlets including BleepingComputer and ABC News, but was not independently confirmed by Genea. As is common with ransomware groups, the gang published sample files to validate its claims and pressure the victim; the specific method of initial access was not publicly confirmed.
Genea said the unauthorised third party accessed folders on its patient management system that could contain full names, dates of birth, emails, addresses, phone numbers, Medicare card numbers, private health insurance details, medical record and patient numbers, medical histories, diagnoses and treatments, medications and prescriptions, pathology and diagnostic test results, doctors' and specialists' notes, appointment details, and emergency contacts and next of kin. A Defence DA number was also listed among the data categories. The Australian Passport Office later confirmed that compromised details may have included Australian passport information. Genea said there was no evidence at that stage that financial information such as credit card or bank account details had been taken, though its investigation was ongoing.
The threat actors claimed to have stolen roughly 700 GB of confidential and personal client data, which they began leaking on the dark web. However, a court order referenced in reporting indicated that around 940.7 GB of data was actually extracted from Genea's systems on 14 February 2025. The stolen records reportedly spanned around six years.
Reportedly, yes. The Australian Passport Office and the Department of Foreign Affairs and Trade (DFAT) confirmed they were aware of the incident and that the compromised personal details of some clients and staff may have included Australian passport information. Genea also listed Medicare card numbers and private health insurance details among the categories of data held in the affected patient management system. Affected individuals were advised to remain vigilant against identity theft and fraud, and support was offered through IDCARE, Australia's national identity and cyber support service.
According to a court order referenced in media reporting, the attackers were inside Genea's network for more than two weeks before being detected, with access believed to have begun around 31 January 2025. Genea identified the suspicious activity on 14 February 2025, the same day a large volume of data was reportedly exfiltrated. The specific vulnerability or technique used to gain initial access was not publicly confirmed.
There is no public confirmation that Genea paid a ransom. Rather than pay, Genea obtained a court-ordered injunction to prohibit the access, use, dissemination or publication of the stolen data, engaged external cybersecurity partners, and worked with Australian authorities including the Australian Federal Police. The threat actors nonetheless published stolen data on the dark web.
Patients were significantly disrupted. Genea's phone lines went down on 14 February 2025, and the MyGenea app — which patients use to track their cycle and view fertility data, results and forms — became inaccessible. Many patients struggled to reach their clinics for urgent treatment matters such as blood slips and medication refills, and some said the delays affected their fertility treatment. Patients also expressed considerable anxiety and distress about the exposure of deeply private medical information, and were later warned that their data had likely been accessed and published.
Genea took affected systems and servers offline as a precaution, engaged external cybersecurity partners and the public-relations firm Porter Novelli, and worked to bring its core systems back online securely. It obtained a court-ordered injunction to restrict access to and publication of the stolen data, notified the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC), and reported the matter to the Australian Federal Police. Genea also made identity-protection support available to affected individuals through IDCARE.
Genea notified the OAIC and the ACSC and met with the National Office of Cyber Security and other government departments. The National Cyber Security Coordinator, Michelle McGuinness, said she was coordinating a whole-of-government response and urged the public not to seek out or access the stolen data on the dark web. The Australian Federal Police opened an investigation following the publication of the leaked data, and DFAT engaged on the potential exposure of passport information.
The Genea incident shows how damaging a healthcare data breach can be when highly sensitive medical and identity information is exposed, and how weak crisis communication can compound patient harm and distress. The key lessons are to detect intrusions faster — the attackers reportedly had weeks of undetected access — to protect, encrypt and segment sensitive patient data, to prepare clear breach-notification and communication plans for affected individuals, and to rehearse incident response before a crisis hits. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.