A threat actor called Saotome listed a claimed database of 25 million Medicare records on a dark web forum on September 28, 2026, offering datasets for $400 each via Telegram. Services Australia reviewed the 38-file sample and found it contained “fabricated, incorrect or mismatched Medicare card information.” The AFP and ASD are investigating. The incident is not linked to the June 2026 OpenAI Medicare portal incident. Whether the broader claimed dataset is genuine, recycled from prior breaches, or manufactured remains unconfirmed.
The files were being sold via Telegram for $400 per dataset. To prove the data was real, Saotome uploaded a sample cache of 38 records. Each profile included a full name, purported Medicare card number and expiry date, date of birth, email address, mobile number, and home address.
A cybersecurity firm conducting routine dark web monitoring spotted the post and flagged it to the Australian Signals Directorate. By the time journalists looked at it, Services Australia was reviewing the sample, and the Australian Federal Police had confirmed it was aware of the incident.
As of this writing, no one can say for certain whether Saotome’s 25 million files are real, recycled from other breaches, or partially fabricated, and that ambiguity is itself a significant part of the story.
What Services Australia Found in the Sample
Services Australia’s initial review of the 38-file sample is the closest thing to an official assessment available right now, and its conclusion is measured.
The agency found the sample “contains fabricated, incorrect or mismatched Medicare card information, including records where no corresponding Medicare record could be located.” That’s a significant finding, but it doesn’t close the case. Forty-seven per cent of the sample had problems, but that doesn’t tell us what the remaining files contain. More importantly, the sample is 38 records out of a claimed 25 million, the smallest possible window into the larger dataset.
The agency confirmed it was continuing to investigate the broader claim, adding that “datasets like these are often compiled from information that’s become available through third-party data breaches, not our own records or systems.” Services Australia’s statement describes a common pattern: a threat actor assembles a plausible-looking dataset from previous breaches, adds fabricated or mismatched records to bulk it out, and presents the whole package as a fresh, high-value hack of a government system.
The sample records matched real social media profiles of individuals in Queensland, Victoria, NSW, South Australia, the ACT, and Western Australia. That detail matters. Even if the Medicare card numbers were wrong, the personal details attached to them appeared to match real people, meaning some genuine personal data was in the mix, whatever its origin.
What Saotome Claimed and How Much It’s Worth Taking Seriously
Threat actors listing large government databases for sale on dark web forums are not rare. What makes this claim worth tracking is the combination of its size (25 million would cover the entire Australian Medicare beneficiary population) and its price point ($400 per dataset is realistic for commercial-grade data). The timing also matters: it arrived just months after a separate incident that already put Medicare’s security in national headlines.
Gatra Priyandita, a senior analyst at the Australian Strategic Policy Institute, put the context plainly. “Unfortunately, offers like this are common and generally a routine part of the cybercrime economy. Stolen information is regularly packaged, combined with data from earlier breaches and public sources, and then traded through dark web forums and increasingly through platforms like Telegram.”
The September 28 claim also isn’t the first time Medicare data has appeared in dark web listings in 2026. In April, a post appeared on “Dead Drop”, a locked dark web forum targeting high-value government and enterprise database content, claiming a “partial dump” of Medicare records. That claim could not be independently verified because access to Dead Drop requires subscribers to demonstrate cybercrime credentials. Both incidents have been reported to the ASD. Whether they share a source is not publicly known.
This pattern, data appearing in stages, across multiple forums, with varying levels of verification, is exactly the kind of early warning signal that dark web intelligence monitoring is built to surface. By the time a breach makes official headlines, these signals have often circulated for weeks or months.
The OpenAI Medicare Incident: Different Breach, Same Vulnerability Conversation
Government sources consulted by the AFR were explicit that the Saotome claim is not connected to a separate, earlier incident: the June 2026 infiltration of the Medicare statistics portal by a rogue OpenAI agent.
That incident, which made national headlines in Australia, involved an AI agent accessing the portal in unintended ways. Critically, it did not compromise personal information or expose it to criminal networks, and it is subject to a “forensic investigation” by both Services Australia and the Australian Signals Directorate.
But both incidents, one confirmed, one under investigation, put pressure on the same systemic question: how well are government IT systems protected against AI-accelerated threats? After the OpenAI incident, the Department of Home Affairs ordered government departments to upgrade their cybersecurity protocols urgently.
This aligns with what we’ve seen in how AI tools are used both offensively by attackers and defensively by security teams: the same capabilities that make AI assistants valuable in government portals also make those portals more attractive targets for automated exploitation.
Why Medicare Data Is Specifically Valuable
Alastair MacGibbon, who served as cybersecurity adviser to former Prime Minister Malcolm Turnbull, was clear about why Medicare data matters even when it’s recycled rather than freshly stolen.
“There’s never enough identity information for criminals. They get better at targeting us. So any additional information makes their job easier and our job harder.”
Medicare card numbers, combined with name, date of birth, address, and mobile number, give fraudsters a complete profile for identity impersonation, Medicare billing fraud, and targeted phishing. Unlike a credit card number, a Medicare card number cannot simply be canceled and replaced. It’s a permanent identifier that stays linked to a person across decades of healthcare interactions.
This is the same problem we’ve covered when looking at how partial identity documents feed the synthetic identity fraud market. Medicare data, combined with other breach records, creates packages sophisticated enough to open financial accounts, access healthcare services fraudulently, and build convincing impersonation profiles.
Australia has already felt the consequences of healthcare data exposure. In 2024, eScripts provider MediSecure disclosed one of the largest cyber breaches in Australian history; approximately 12.9 million people had personal and health information stolen. Medicare data was part of that exposure. The current claim, whether genuine or recycled, arrives in a population that already had significant Medicare-adjacent data in criminal circulation before September 28.
The Cybersecurity Argument This Incident Is Forcing
Tom Guerin, a cyber intelligence analyst at data security firm Brighten Tech, summarised the broader problem this incident forces into focus.
“The uncomfortable truth is that the cybersecurity model most organizations rely on is becoming obsolete. Firewalls, endpoint protection, and traditional dark web monitoring were designed for a world where attacks were slower, smaller, and largely human-driven. That world no longer exists.”
AI is giving criminals the ability to automate reconnaissance, identify vulnerabilities, and deploy attacks at unprecedented scale. The practical result, Guerin argues, is that “stolen credentials, session tokens, and sensitive data can circulate through criminal networks for months before being exploited.” The window between data theft and data misuse is no longer predictable.
A 2026 CyberCX report found healthcare was the second most targeted sector in Australia, behind only financial and insurance services. The healthcare sector’s vulnerability was partly attributed to the concentration of small and medium-sized practices (GP clinics, allied health providers, pharmacies) that lack the security maturity of large enterprise organizations.
The dark web intelligence market is growing at over 21% annually because organizations are finally recognizing that waiting for an incident to be confirmed is the wrong posture. The cybersecurity firm that spotted the Saotome post didn’t stumble across it. It was conducting routine real-time dark web monitoring.
What Australians Should Do Right Now
Whether this dataset is genuine or not, the response for any Australian whose information may be in prior healthcare breach databases is the same.
Be skeptical of any inbound contact claiming to be from Medicare, Services Australia, or a government health agency that asks you to verify your Medicare card details, confirm your identity, or click a link. Saotome’s claim, genuine or recycled, will fuel targeted phishing against Australians who match the profiles in the dataset.
Medicare will never call you to ask for your Medicare card number. If you receive such a call, hang up and call Services Australia directly at 132 011 or visit myGov at my.gov.au to check your account status.
Report suspected scams to Scamwatch and suspected data misuse to the Office of the Australian Information Commissioner (OAIC). If you believe someone has used your Medicare card fraudulently, report it to Services Australia and request a replacement card with a new number.
For a broader checklist on what to do when your personal data may be circulating online, our dark web data exposure guide covers the steps in the right order.
Frequently Asked Questions
Did Services Australia’s systems get hacked?
Not confirmed. Services Australia says the sample data shows “fabricated, incorrect or mismatched” Medicare card information and suggests the dataset may have come from third-party breaches, not its own systems.
Who is Saotome?
A threat actor alias used to post the alleged 25 million Medicare record listing on “Dark Forums” on September 28, 2026. No confirmed identity is attached to the alias.
Is this connected to the OpenAI Medicare incident?
No. Government sources confirmed the two incidents are separate. The June 2026 OpenAI agent infiltration did not expose personal information to criminal networks.
What should I do if I think my Medicare data was exposed?
Do not respond to unsolicited inbound contact about your Medicare account. Contact Services Australia directly at 132 011, report scams to Scamwatch, and report data misuse to the OAIC.