Microsoft has quietly disclosed that it played a “key role” in feeding information to the Australian Signals Directorate (ASD) that helped identify who was behind the 2022 Medibank cyber attack.The federal government yesterday publicly attributed the attack to Aleksandr Ermakov, a 33-year-old Russian national whose aliases included Alexander Ermakov, GustaveDore, aiiis_ermak, blade_runner, and JimJones.
It also announced “targeted financial sanctions” and a travel ban against Ermakov. The financial sanctions make it a crime to provide assets to Aleksandr Ermakov, or to use or deal with his assets, including through cryptocurrency wallets or ransomware payments.
In a glimpse behind the scenes of the investigation, Microsoft A/NZ national security officer Mark Anderson wrote that “behind closed doors there are exceptionally talented people collaborating across the Australian government and organizations like Microsoft to track these criminals.”
The meat of Microsoft’s input into the investigation came through its threat intelligence center, Anderson wrote.
”Microsoft’s Threat Intelligence Centre (MSTIC) played a key role in providing evidence to support the investigation into the Medibank cyber attack,” he wrote.
“MSTIC tracks more than 300 unique threat actors, including 160-plus nation-state actors and 50-plus ransomware groups daily.”This, he said, was an example of the importance of global public and private partnerships to such investigations.“Each identification of cybercriminals and disruption of cybercrime infrastructure brings forward lessons learned.”
New Cyber Security Research Centre
Microsoft’s disclosure comes as the Australian government is increasingly focused on cybersecurity threats. In December, the government announced a $1.9 billion cybersecurity strategy that includes plans to establish a new Cyber Security Research Centre and to boost the ASD’s capabilities.
The Medibank cyber attack was one of the largest data breaches in Australian history. The attack affected the personal information of millions of Australians, including their names, addresses, dates of birth, and medical records.
The attack is believed to have been carried out by a group of Russian hackers who are known for targeting healthcare organizations. The hackers are believed to have gained access to Medibank’s systems through a phishing attack.
Microsoft’s role in the investigation into the Medibank cyber attack is a reminder of the importance of private-public partnerships in cybersecurity. Governments and businesses need to work together to share information and to develop new ways to combat cyber threats.

