Partnered Health confirmed that a cyberattack on June 23 compromised data from 21 clinics located in New South Wales, Victoria, Queensland, Western Australia, and the ACT.
The breach, which occurred between April and September 2023, was the result of credential-stuffing attacks that compromised the data of 6.9 million customers, including sensitive genetic ancestry information.
The data exposure occurred through a sophisticated vishing attack where a threat actor, posing as IT support, tricked a contact center agent into visiting a malicious website.
The breach, which Miinto reported to the police and data protection authorities, may have compromised customer names, email addresses, physical addresses, and phone numbers.