Genea, an IVF provider, suffers a significant data breach.
February 19, 2025
Genea is a large IVF provider has suffered a cyber attack. Today publicly announced that it has been the subject of a cyber attack. The statement, 19 February 2025: Important update about a cyber incident, is a model of saying precious little.
It provides:
Are Genea clinics still open and treatments being provided?
What should I do?We will communicate with relevant individuals if our investigation identifies any evidence that their personal information has been impacted.
Need to get in touch?
The statement is more about appearing to provide information while not doing any such thing. There are no details of when the attack occurred, when it was detected, what data was accessed. The ABC’s sleuthing partially filled in those gaps. The ABC suggests the attack occurred sometime on the weekend when Genea’s phone line went down (which it announced on 14 February – last Saturday) and its app was unusable and patients started posting on Genea’s Instagram account. It claims to be investigating the extent to which personal information has been accessed. That is improbable. If it is accurate then the resources it is deploying to determine whether personal information accessed is inadequate. So Genea’s vague say not much media release is less than helpful. IVF patients have a very strong interest in using the digital resources of Genea, are very proactive and many are quite sophisticated. So throwing a digital blanket over a serious breach is a poor way of managing a crisis. The reluctance by Genea to be more open may expose it to more media coverage.
Given the nature of the treatment provided and the likelihood that very sensitive personal information was stored in Genea’s records it is almost certainly a notifiable data breach.
The story has been reported in Read the rest of this entry »