CSIDB logo
Incident

Riverina Medical & Dental Aboriginal Corporation

Incident posture

Attack window
Feb 2025
Location
Australia
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 16:40

Linked entities

Victim
Riverina Medical & Dental Aboriginal Corporation
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An unauthorised criminal actor accessed part of the IT systems of this Aboriginal medical and dental organisation, prompting immediate engagement of external cyber experts to investigate and contain the incident. The organisation reported the matter to the Office of the Australian Information Commissioner and engaged IDCARE as a specialist provider to support affected community members, clients, and staff. Management and the board stated the incident was not caused by any staff member and that prior cybersecurity systems were in place, noting that the attack involved a cybercriminal bypassing complex security measures. While the investigation remained ongoing, the organisation indicated there was no evidence that accessed personal information had been or would be made publicly available, and committed to contacting individuals once the scope of impacted data was determined.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

3 techniques

Description

Riverina Medical & Dental Aboriginal Corporation, operating publicly as RivMed, disclosed a cyber incident that it became aware of shortly before late February 2025. According to a notice published on 26 February 2025, an unauthorised person committed a criminal offence and accessed a part of RivMed's IT systems. Upon becoming aware of the intrusion, RivMed immediately engaged leading cyber experts to advise on how to respond. While the investigation was ongoing, the organisation confirmed that the incident had been contained, and its team was working urgently to protect the privacy of community members and staff.

As soon as the organisation determines what personal information was accessed during the incident, it stated it would contact affected individuals in line with its obligations. RivMed reported the incident to the Office of the Australian Information Commissioner. The organisation placed the wellbeing of its community members, clients and staff as its highest priority and committed to supporting those affected. A specialist provider, IDCARE, was engaged to support the community in responding to any questions about the incident. RivMed also provided a dedicated support email address, [email protected], for community members seeking further information or support.

In a follow-up update published on 28 February 2025, RivMed's management team and board addressed several questions that had been raised by the community regarding the nature and handling of the incident. The organisation confirmed that the incident was not caused by the actions of a staff member, explaining that prior to the incident RivMed had numerous cyber security systems in place to protect its information. RivMed's expert partners advised that cyber incidents were on the rise globally and that criminals were targeting organisations of all sizes, with these events often described as highly sophisticated and involving cybercriminals bypassing complex IT security.

RivMed also explained the time taken to communicate about the incident, stating that cyber experts were brought in immediately upon discovery to provide advice and assist with the response. Management and the board worked urgently with these experts to investigate the incident, with investigations described as extremely complicated and time-consuming. The organisation indicated it was important to protect the integrity of the investigative work while it was being undertaken. Management and the board wanted to ensure they had accurate information before informing the community, stating they did not want to cause unnecessary alarm by communicating information that could later prove to be incorrect.

Regarding the protection of staff, member and client data, RivMed stated that management and the board took all possible steps to prevent any accessed information from being published online. RivMed affirmed that community, members, clients and staff were its highest priority. At the time of the update, the organisation stated there was no evidence that personal information had been or would be made publicly available, meaning no one else in the community would be able to access that information. Ongoing monitoring by RivMed's experts was also in place.

Regarding governance, RivMed confirmed that the management team had been meeting regularly with board members since the incident was discovered. All major decisions were made by the elected board members, who had been involved in all stages of the incident. RivMed reiterated its commitment to supporting its community, members, clients and staff in relation to the incident, with IDCARE continuing to provide specialist support for community concerns. The organisation again directed any further questions or support requests to [email protected], signed off by the RivMed Board and management.

Sources

Sources available to members: 1 source.

CSIDB