The Essendon-headquartered SIA Medical Centre has said it is investigating a cyber security incident after hackers claimed to have accessed sensitive patient data.
“SIA Medical is aware of a cyber incident involving unauthorised access to a portion of its systems,” an SIA spokesperson told Cyber Daily.
“As soon as we discovered the incident, we engaged cyber experts to provide advice, take steps to contain the incident, and assess the nature and extent of any personal information that may have been accessed.”
The investigation follows the Rhysida ransomware group listing SIA Medical in a 12 August post on its darknet leak site.
“We are pleased to present: ~20,000 patient medical records – names, dates of birth, Medicare numbers, clinical notes, insurance and work-cover files, full patient dossiers,” Rhysida said.
“Staff identity documents – passports, driver’s licenses, police checks, tax file declarations of doctors and employees.”
In addition, the hackers claim to have accessed login credentials, HR records, subpoenas, and banking details. The complete dataset is currently being offered to any buyer for six bitcoins, with a full publication date of 19 August.
SIA Medical said it is aware of the hackers’ claims.
“As part of our investigation, SIA Medical has become aware that an unknown third party has named our organisation online and published a small number of documents it claims were taken from our system,” SIA said.
“We are investigating this activity as a priority and have sophisticated monitoring in place to detect any developments. We are also in the process of notifying those individuals whose information was contained in the small number of published documents.”
SIA Medical said it will continue contacting individuals if more data comes to light, and that it has informed the Office of the Australian Information Commissioner and the Australian Cyber Security Centre.
“This incident has not impacted our practice’s ability to provide services to patients,” SIA said.
“We take cyber security seriously and will ensure that all appropriate action is taken in response to this incident.”
Who is Rhysida?
Rhysida’s first activity dates back to mid-2023, and the group has claimed 275 victims in that time.
The group claims to be purely financially motivated and has been observed communicating online in Russian.
In August 2023, the gang attacked healthcare organisation Prospect Medical Holdings, causing disruptions across 17 hospitals and 166 clinics in the United States. That attack saw 500,000 Social Security numbers, medical data, and passport details posted for sale on the gang’s leak site. In January 2025, the group claimed to have stolen more than three terabytes of data from the US-based Sunflower Medical Group, a hack that impacted more than 400,000 patients.
The gang’s most recent Australian victim was Queensland-based medical centre Harbour Town Doctors, which was listed on Rhysida’s leak site in December 2025.
Who is SIA Medical Centre?
SIA Medical opened its first clinic in the Melbourne suburb of Essendon in 1993 and has since expanded to several more locations in the area, with clinics in Box Hill, Burwood, Croydon, Essendon, Footscray, Moonee Ponds, Montrose, Mulgrave, and Berwick.
Its services include general practice, dental services, pathology, and travel medicine.
“We service a growing population of diverse patients, ranging from families to young professionals and refugees, which varies from clinic to clinic,” SIA Medical said on its website.
“All clinics are fully accredited and with some providing teaching to GP registrars and medical students.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.