Medibank Private Limited (MPL) Earnings Call Transcript & Summary

October 16, 2022

Australian Securities Exchange AU Financials Insurance special 17 min

Earnings Call Speaker Segments

David Koczkar

executive
#1

Good morning all, and thank you for joining us at such short notice. I'll begin by acknowledging the traditional owners and custodians of country throughout Australia and recognize their connections to land, sea and community. I join you today from Naarm, the home of the Wurundjeri Woi Wurrung peoples. I pay my respects to their elders past, present and emerging, and I extend my respect to all elders on the land on which we work and live. This morning I'm joined by our executive leadership team, including our Group Executive Technology and Operations, John Goodall; and Group Executive, Customer and Brands, Rob Deeming. We called today's investor briefing to update you all on the cyber incident we alerted the market to on Thursday last week. As you would have seen in our update to the market this morning, we can confirm that our ongoing investigations continue to show there remains no evidence that customer data has been removed from our IT environment after we detected unusual activity last week in part of our IT network. And I'm pleased this morning to confirm that normal operations have resumed. We have contained the ransomware threat, but remain vigilant, and we'll take the necessary steps in the future to protect our operations and customers' data. I'll now take a couple of minutes to talk you through a timeline of the major events relating to the incident. On Wednesday last week, unusual activity was detected by our cybersecurity systems. This led to our cybersecurity team commencing their incident response, supported by our cybersecurity partners. Later that evening, we identified the unusual activity was focused on the IT infrastructure, which supports our ahm and international student customer policy management systems. We took the precautionary step to take the systems offline to protect the data of our customers. This decision was taken out of an abundance of caution and gave us the ability to temporarily block and isolate access to these systems. Given we were at that time dealing with a degree of uncertainty, we felt that it was prudent to inform the market and entered into a trading halt on Thursday morning. We did this to ensure that we met our continuous disclosure obligations, given our primary obligation is to operate in an informed market. Over the course of Thursday, the systems were restored on new IT infrastructure, allowing normal activity to resume for the ahm and international student customers business on Friday, 14th of October. On Thursday, we also started to communicate to our customers by emails and text to keep them informed about the incident. On Friday, the ahm and international student customer policy management system experienced some performance issues largely resulting from a higher volume of customer calls after the system had been offline on Thursday. We, therefore, temporarily restricted customer access via the web to improve performance of that system for our team members and also for our customers, with our team members being able to handle customer calls and to ensure that customers could continue to make claims by our phone team. The system was brought back up on Friday night. And due to these higher volumes, we decided to open the ahm call center last Saturday. As I said earlier, we have now contained the ransomware threat, but remain vigilant and we'll take necessary steps in the future to protect our operations and the data of our customers, our people, and all our stakeholders. Our investigation, which is ongoing, indicated that our cybersecurity systems had detected activity consistent with the precursor to a ransomware event. This initial filing was shared with the Australian Cybersecurity Center, who provided us with additional guidance in support of this conclusion. We believe compromised credentials were used to access our systems. I can confirm that our investigation shows that systems were not encrypted by ransomware during this incident. And there is also no indication that the incident was caused by a state-based threat actor. As a health company providing health insurance and health services, we obviously hold a range of necessary personal information of customers, and the protection of our customers' data security is our highest priority. Despite the decision to temporarily block and isolate our ahm and international student policy management systems, customers were able to access health services and their health providers during this time. As you would expect, we are continuing to work with external parties to provide them with assurance about this incident and our recovery. I would like now to take this opportunity to, again, apologize to our customers. We understand this news may have caused concerns and inconvenience for some of our customers. We took the necessary precautions to protect the data of our customers, people and other stakeholders. I thank our customers for their patience during this incident. We take the protection of our customers' data very seriously. And to reiterate, there remains no evidence that customer data has been removed from our network. We will provide updates if the situation changes. And at this stage, we do not expect significant costs associated with either managing or mitigating this incident. I would like to thank the Australian Cybersecurity Center, regulators and government departments who have contributed to and supported our response and worked so effectively with us. We will also share technical information with our peers as part of our commitment to helping others understand this incident and allow them to bolster their own defenses. While we will remain vigilant and we'll continue to take necessary action to further safeguard our networks and data for our customers, I could not be more proud of how our people have come together to respond to this incident for our customers. And I would like to thank them for remaining focused on supporting the health and well-being of our customers. As I said earlier, we have resumed normal operations and do not expect this short disruption to impact the performance of the business. As such, it will be great to keep the questions focused on the cyber incident itself. So I'll now hand over the call for any questions you may have.

Operator

operator
#2

[Operator Instructions] The first question comes from Kieren Chidgey from Jarden.

Kieren Chidgey

analyst
#3

David, a couple of questions, if I could. Maybe just starting on the attack. I mean, you've made it clear no data has been removed. I'm just wondering if you can clarify whether or not they actually had access to the data, customer data, that is?

David Koczkar

executive
#4

Yes. Thanks, Kieren. So yes, we know how systems were accessed, and as I said, we've taken all necessary steps to address this. But we believe one of our credentials was compromised. But we've got an ongoing investigation into exactly what happened. And we've got no further detail that we can share at this stage, but we will, if anything comes to life. Again, I'll reiterate, there's no evidence that customer data has been removed from any of our systems.

Kieren Chidgey

analyst
#5

Okay. But they had access to the data? Or is the data encrypted to customer data as well?

David Koczkar

executive
#6

At this stage, we have no evidence that there was any access to customer data, but that really is subject to our continuing forensic analysis. While I think we're very focused on what our customers are focused on, is any evidence that our customer data has been removed, and we can say definitively that there is no evidence that customer data has been removed from our systems.

Kieren Chidgey

analyst
#7

Okay. And off the back of this, what additional sort of measures did you envisage or believe you might need to put in place to sort of further strengthen systems? And how should we think about sort of cost and locations as a result of that?

David Koczkar

executive
#8

Well, I think as I said before, our systems actually detected this unauthorized and unusual access across our network. The teams are formed and managed the incident response, and we've been able to contain the ransomware threat. We obviously are going to have a full review, including our forensic investigation, and that will form the basis of any updates going forward. But at this stage, we do not expect the impact of this issue to have any material cost to our business.

Kieren Chidgey

analyst
#9

And just a final question on the trading update, which you've said it's tracking in line with the outlook for '23. Can you just give a bit of commentary around the claims inflation environment and policyholder growth? I presume both those trends are sort of moving in line with your '23 targets individually?

David Koczkar

executive
#10

Yes. So look, I think for the 3 months to 30 September, we've continued to show good momentum and are tracking in line with the FY '23 outlook we provided at the results. And we don't expect this short disruption to impact that momentum. So we'll give further update as part of our ongoing disclosure requirements at the AGM.

Operator

operator
#11

Next question comes from Andrew Buncombe from Macquarie.

Andrew Buncombe

analyst
#12

Just one question from me, please. Do you have cyber insurance cover?

David Koczkar

executive
#13

Thanks, Andrew. Look, we're in the business of managing risk. And so from a cost perspective, we self-insure. I think the key thing that we think about is access to the right experts and support services that we might need in the event of a cyber incident. I think what we have now seen is that we're able to access those support services in the right time frame. And so we're very happy with how we sit in terms of our ability to respond to a cyber incident. However, from this incident, there will be some learnings we'll conduct and complete our forensic analysis, and we'll continue to learn and evolve as we go forward.

Andrew Buncombe

analyst
#14

Sure. Maybe just a quick follow-up then, please, and maybe ask Kieren's question in a different way. So less about what further investment needs to go into the technology side, but what sort of costs do you expect to incur on consultants and advisers this year? And I assume that's going to sit outside of the current cost guidance.

David Koczkar

executive
#15

Well, as I said before, although it's early days, we do not expect there to be any material cost outside the guidance we've given dealing with this incident. And if we'll provide any update to outlook at the AGM.

Operator

operator
#16

[Operator Instructions] Your next question comes from Siddharth Parameswaran from JPMorgan.

Siddharth Parameswaran

analyst
#17

Just to understand what actually was accessed. I don't know if you can provide some details. I didn't quite understand exactly where the breach occurred and what was accessed. I mean I know you said what wasn't access, but just what was accessed?

David Koczkar

executive
#18

Well, I think as I said before, we discovered the unusual activity in part of our network. That was in the infrastructure that supported the ahm and international students business system. That's why we took the step to bring that system down and we rebuilt it on new IT infrastructure. There has been no evidence that customer data has been removed from any system. But as I said before, we will continue to investigate this incident as part of our ongoing forensic analysis.

Siddharth Parameswaran

analyst
#19

Yes. Okay. But I mean still I'm not quite clear -- I mean it's clear that the policy data wasn't accessed and it's clear that you're saying that the ahm and the international student data seems to being accessed. But I mean, there's a lot there that isn't clear in terms of what actually was accessed. I'm just trying to understand, the system, what does that mean? I mean, is it just the front end? I don't know what you can provide, but just if you could give us some components as to what actually was accessed.

David Koczkar

executive
#20

Sure. So as I said, the unauthorized access and the unusual activity we saw in the infrastructure, so that's not the system, the infrastructure that supports our ahm and international students business. And that's why we took down the system and we rebuilt it on new infrastructure or the platform effectively that it sits on. We've also deployed additional security measures across our whole network to strengthen the integrity of our systems. So see, we are doing a forensic analysis to ensure ourselves that we will understand fully what happened in the past. But as I can say right now, we've contained the ransomware threat. But again, as I said, we'll remain vigilant and take necessary steps in the future to protect our operations and the data of our customers.

Siddharth Parameswaran

analyst
#21

Okay. Maybe just another question. Just the Medibank policyholders' data or Medibank systems weren't accessed. Are they on a separate system? Or -- I'm just wondering how that was isolated?

David Koczkar

executive
#22

Yes. So again, we said that we discovered this unusual activity at the infrastructure level that supported the ahm and international students customer management system. The Medibank brand sits on a separate system. And so we didn't detect any activity that was unusual at this stage there. So that's why we isolated our response to the ahm and international students customer management system. However, as I said, we've deployed additional security measures across our entire network to strengthen the integrity of all our systems.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Medibank Private Limited transcript — plus 253,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Medibank Private Limited earnings transcripts and 253,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.