CSIDB logo
Incident

Genea

Incident posture

Attack window
Feb 2025
Location
Australia
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-02 17:32

Linked entities

Victim
Genea
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Feb 2025
Disclosed
Feb 2025
Resolved
Feb 2025

Summary

A fertility services provider is urgently investigating a cyber incident after detecting suspicious activity on its network. Upon discovery, the organization took immediate steps to contain the incident, including taking certain systems and servers offline, which are now being progressively restored as the investigation continues. The investigation has confirmed that an unauthorized third party accessed company data, and efforts are underway to determine the nature and extent of the information involved, particularly any personal data. The organization is working to minimize disruption to patient treatments and clinic operations, noting that patients who have not been contacted by their local clinic should continue their scheduled treatments without change. Affected individuals will be notified if evidence emerges that their personal information was impacted, and the organization has apologized for any concern caused while reaffirming its commitment to data privacy and security.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

3 techniques

Description

On 19 February 2025, Genea, an Australian fertility services provider, publicly disclosed that it was urgently investigating a cyber incident after identifying suspicious activity on its network. The company stated that as soon as the incident was detected, immediate steps were taken to contain the incident and secure its systems. Out of an abundance of caution, Genea took some of its systems and servers offline while the investigation was conducted. These systems and servers were subsequently being restored while the investigation continued, indicating a phased approach to both containment and recovery.

Genea's ongoing investigation identified that an unauthorised third party had accessed Genea data. At the time of the disclosure, the company was urgently investigating the nature and extent of the data that had been accessed, as well as the extent to which that data contained personal information. Genea acknowledged the importance that individuals place on their information, particularly in the context of the current threat environment, and committed to keeping affected parties updated as more information became available through the investigation. The company also established a dedicated communication channel, providing an email address, [email protected], for individuals seeking further information about the incident.

Regarding operational impact, Genea communicated that it was working hard to ensure minimal disruption to treatment being provided to its patients. The company indicated that unless patients heard directly from their local Genea clinic, there was no change to their current treatment schedule. Genea reassured patients that its teams of specialists, nurses, and office support staff were working tirelessly to ensure that there was minimal disruption to treatment, which it described as being of utmost priority and importance. The company also stated that it would communicate with those individuals whose personal information was identified as having been impacted by the incident as the investigation progressed. Genea offered a sincere apology for any concern the incident might cause and emphasised its commitment to patient privacy and data security.

Sources

Sources available to members: 1 source.

CSIDB