Cyber-Attack Timeline: Genea

Educational & easy-to consume visual guides to understanding attacks & enhancing resilience

Genea Timeline Genea TL Summary (1)

Download Our Educational Cyber-Attack Timeline: Genea

Australian IVF provider, Genea, was attacked by the Termite ransomware group with attackers, allegedly, stealing 700 GB of highly sensitive patient and publishing it on the dark web. This included highly personal and confidential information of Genea's IVF patients, such as medical histories, Medicare numbers, passport data, contact details, and test results.

The attack caused significant disruption to Genea's operations, with phone lines going down and the MyGenea app becoming inaccessible, leading to patient anxiety and frustration. The breach was detected on February 14, 2025, after suspicious activity was observed on the network, but the impact quickly escalated as patients struggled to contact clinics for urgent medical inquiries and treatment plan updates.

We’ve captured everything that took place in this major healthcare data breach in our Genea Cyber Attack Timeline and Visual Summary Image.  

 

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of the detailed Genea Cyber Attack timeline document and summary.

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs on the Genea Cyber Attack

  • 1. What happened in the Genea cyber attack?

    In February 2025, Genea — one of Australia's largest IVF and fertility providers — confirmed it had been hit by a cyber attack after an unauthorised third party accessed its network. The incident, reportedly carried out by the Termite ransomware group, disrupted Genea's phone lines and the MyGenea patient app, and led to a large volume of sensitive patient data — reportedly more than 700 GB — being stolen and later published on the dark web. Genea notified Australian regulators, obtained a court-ordered injunction to limit the spread of the leaked data, and engaged cybersecurity partners and law enforcement. Because the stolen information included highly sensitive medical, fertility and identity records, it became one of the most serious healthcare data breaches in Australia in 2025.

  • 2. When did the Genea cyber attack take place?

    Genea became aware of suspicious activity on its network on 14 February 2025, the same day its phone lines went down. A court order later cited in reporting indicated the attackers had been inside Genea's network from around 31 January 2025 — more than two weeks before detection — and had extracted data on 14 February. Genea publicly confirmed the cyber incident on 19 February 2025, the threat actor began publishing stolen data around 26 February, the Australian Passport Office responded on 28 February, and Genea confirmed that further data had been leaked on 4 March 2025.

  • 3. Who was behind the Genea cyber attack?

    The attack was reportedly carried out by the Termite ransomware group, which claimed responsibility and posted samples of stolen data on its dark web leak site. The attribution was reported by threat-intelligence sources such as HackManac and covered by outlets including BleepingComputer and ABC News, but was not independently confirmed by Genea. As is common with ransomware groups, the gang published sample files to validate its claims and pressure the victim; the specific method of initial access was not publicly confirmed.

  • 4. What data was stolen in the Genea data breach?

    Genea said the unauthorised third party accessed folders on its patient management system that could contain full names, dates of birth, emails, addresses, phone numbers, Medicare card numbers, private health insurance details, medical record and patient numbers, medical histories, diagnoses and treatments, medications and prescriptions, pathology and diagnostic test results, doctors' and specialists' notes, appointment details, and emergency contacts and next of kin. A Defence DA number was also listed among the data categories. The Australian Passport Office later confirmed that compromised details may have included Australian passport information. Genea said there was no evidence at that stage that financial information such as credit card or bank account details had been taken, though its investigation was ongoing.

  • 5. How much data was stolen in the Genea breach?

    The threat actors claimed to have stolen roughly 700 GB of confidential and personal client data, which they began leaking on the dark web. However, a court order referenced in reporting indicated that around 940.7 GB of data was actually extracted from Genea's systems on 14 February 2025. The stolen records reportedly spanned around six years.

  • 6. Were passports and Medicare details exposed in the Genea breach?

    Reportedly, yes. The Australian Passport Office and the Department of Foreign Affairs and Trade (DFAT) confirmed they were aware of the incident and that the compromised personal details of some clients and staff may have included Australian passport information. Genea also listed Medicare card numbers and private health insurance details among the categories of data held in the affected patient management system. Affected individuals were advised to remain vigilant against identity theft and fraud, and support was offered through IDCARE, Australia's national identity and cyber support service.

  • 7. How long were the attackers inside Genea's network?

    According to a court order referenced in media reporting, the attackers were inside Genea's network for more than two weeks before being detected, with access believed to have begun around 31 January 2025. Genea identified the suspicious activity on 14 February 2025, the same day a large volume of data was reportedly exfiltrated. The specific vulnerability or technique used to gain initial access was not publicly confirmed.

  • 8. Was a ransom paid in the Genea cyber attack?

    There is no public confirmation that Genea paid a ransom. Rather than pay, Genea obtained a court-ordered injunction to prohibit the access, use, dissemination or publication of the stolen data, engaged external cybersecurity partners, and worked with Australian authorities including the Australian Federal Police. The threat actors nonetheless published stolen data on the dark web.

  • 9. How did the Genea cyber attack affect patients?

    Patients were significantly disrupted. Genea's phone lines went down on 14 February 2025, and the MyGenea app — which patients use to track their cycle and view fertility data, results and forms — became inaccessible. Many patients struggled to reach their clinics for urgent treatment matters such as blood slips and medication refills, and some said the delays affected their fertility treatment. Patients also expressed considerable anxiety and distress about the exposure of deeply private medical information, and were later warned that their data had likely been accessed and published.

  • 10. How did Genea respond to the cyber attack?

    Genea took affected systems and servers offline as a precaution, engaged external cybersecurity partners and the public-relations firm Porter Novelli, and worked to bring its core systems back online securely. It obtained a court-ordered injunction to restrict access to and publication of the stolen data, notified the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC), and reported the matter to the Australian Federal Police. Genea also made identity-protection support available to affected individuals through IDCARE.

  • 11. How did Australian regulators and government respond to the Genea breach?

    Genea notified the OAIC and the ACSC and met with the National Office of Cyber Security and other government departments. The National Cyber Security Coordinator, Michelle McGuinness, said she was coordinating a whole-of-government response and urged the public not to seek out or access the stolen data on the dark web. The Australian Federal Police opened an investigation following the publication of the leaked data, and DFAT engaged on the potential exposure of passport information.

  • 12. What can organisations learn from the Genea cyber attack?

    The Genea incident shows how damaging a healthcare data breach can be when highly sensitive medical and identity information is exposed, and how weak crisis communication can compound patient harm and distress. The key lessons are to detect intrusions faster — the attackers reportedly had weeks of undetected access — to protect, encrypt and segment sensitive patient data, to prepare clear breach-notification and communication plans for affected individuals, and to rehearse incident response before a crisis hits. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.