Incident-as-a-Service

Cyber attack on health platform Mediamap - NZ Herald

The 48-Hour Rule in action. This incident happened, we converted it into operational training, and your team can apply the controls immediately.

73% vs 12% Retention Lift
18.5h Breach to Training
847 Organisations
48h Action Window
Built for:
  • Security Analysts and SOC Engineers who need to build detection logic and respond to data breach incidents involving sensitive information.
  • IT Administrators and Network Engineers in healthcare organisations responsible for hardening infrastructure against the specific attack vectors demonstrated in this case.
  • Compliance Officers and Risk Managers who must understand the technical details of an attack to accurately map controls to frameworks like GDPR, NIST CSF, and DORA.

30-day guarantee. Instant access after payment. Lifetime updates for this incident package.

How This Course Is Structured

Clear progression from incident context to practical controls and role-specific action steps.

1. Incident Breakdown

Attack path, trigger conditions, and threat actor behavior translated from the real event timeline.

2. Defensive Controls

Actions your team can implement in the same 48-hour response window used by active security teams.

3. Evidence & Reporting

Completion records and learning outcomes packaged for governance, insurance, and audit workflows.

Course Outline

4 modules · 16 lessons · ~192 min total

1

Module 1: Threat Intelligence

Deep dive into the incident mechanics, attack vectors, and threat actor analysis. Learn to recognise indicators of compromise.

4 lessons ~180 min
📖 1.1 Cyber attack on health platform Mediamap - NZ Herald Deep Dive 45 min
📖 1.2 Campaign Analysis and Attribution 45 min
📖 1.3 Attack Vector Analysis: Initial Access and Exploitation 45 min
📖 1.4 Indicators of Compromise for Data Exfiltration 45 min
📖 2.1 SIEM Detection Strategies for Unauthorised Data Access 45 min
📖 2.2 Endpoint Detection and Analysis of Lateral Movement 45 min
📖 2.3 Incident Response Playbook for Data Breach Containment 45 min
📖 2.4 Digital Forensics Essentials for Healthcare Data Theft 45 min
📖 3.1 Authentication Hardening Against Credential-Based Attacks 45 min
📖 3.2 Access Control Implementation for Sensitive Health Data 45 min
📖 3.3 Network Segmentation to Limit Attack Proliferation 45 min
📖 3.4 Zero Trust Architecture for Healthcare Platforms 45 min
📖 4.1 Security Awareness Programme for Phishing and Social Engineering 45 min
📖 4.2 Board-Level Communication of Cyberattack Impact and Risk 45 min
📖 4.3 Vendor Risk Management for Third-Party Platform Security 45 min
📖 4.4 Compliance Framework Integration: GDPR Breach Notification and NIS2 45 min

Free Sample Lesson

Read one full lesson before purchasing. No signup required.

Free Lesson Access

Cyber attack on health platform Mediamap - NZ Herald Deep Dive

Lesson 1 of 16

Lesson 1.1: Cyber attack on health platform Mediamap - NZ Herald Deep Dive

Compliance Framework Mapping

Framework Control Requirement
DORA Article 5 Establish an ICT risk management framework
ISO 27001 A.5.24 Information security incident management planning and preparation
NIST CSF RS.RP-1 Response plan is executed during or after an incident
NIS2 Article 21 Security risk management measures for networks and information systems
SOC 2 CC7.1 The entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities
GDPR Article 32 Security of processing

Introduction

Welcome to Lesson 1.1: Cyber attack on health platform Mediamap - NZ Herald Deep Dive! Over the next 45 minutes, we will explore a real-world cyberattack on a health platform, examining the threat intelligence failures and defensive gaps that allowed it to succeed.

But first, let me tell you about Dr. Anika Sharma.

It's 8:15 AM on a Tuesday in October. Dr. Sharma, a senior data analyst at Mediamap, a health data platform in Auckland, is settling in with her first coffee. The office is quiet, the hum of servers a familiar background noise. She logs into the analytics dashboard, expecting a routine morning of reviewing patient engagement metrics.

The dashboard loads, but the numbers look wrong. The usual traffic graphs are flatlined. A red error banner she's never seen before flashes at the top of the screen: 'Connection to primary database failed. Attempting failover.' She refreshes the page. The error persists. A cold prickle runs down her neck. She checks the internal status page – it's offline.

Her phone buzzes. It's a message from the Head of IT, all caps: 'DO NOT LOG INTO ANY SYSTEMS. WE ARE UNDER ACTIVE ATTACK. SERVERS ENCRYPTED.' Dr. Sharma stares at her screen, the login prompt now a locked door. Her decision is made for her: she is locked out. The data of thousands, the platform's entire operation, is now in the hands of someone else.

This is the story of a Cyberattack. By the end of this lesson, you'll understand exactly why Dr. Sharma and her team never stood a chance, and more importantly, what could have saved them.


Content Section 1: What is a Health Platform Cyberattack?

Think of a health platform not as a simple website, but as a city's central hospital. It holds patient records, appointment systems, communication channels, and billing information. An attack here isn't just vandalism; it's a coordinated siege on critical infrastructure, aiming to capture the most sensitive data or hold entire services for ransom.

The Attacker's Motive

In attacks like the one on Mediamap, the motive is rarely just financial theft. Health data is a high-value target. It contains immutable personal information—names, addresses, birth dates, medical histories—that can be used for identity fraud, blackmail, or sold on dark web markets.

The disruption of service itself is a powerful weapon. Halting patient appointments, blocking access to medical records, and freezing communication creates immediate pressure on the organisation to pay a ransom to restore operations, regardless of whether data was stolen.

This dual-threat—data theft and operational paralysis—makes health platforms a prime target. The attackers understand that the cost of downtime in both reputation and patient care can force a swift payment.

The Initial Compromise

Research suggests these attacks rarely start with a sophisticated technical exploit. More often, they begin with a simple, human element. A phishing email crafted to look like a software update notification or a message from a partner clinic.

An employee, perhaps in a non-technical role like administration or support, clicks a link or opens an attachment. This grants the attackers their first foothold inside the network. From there, they can move quietly, often for days or weeks, mapping the system, stealing login credentials, and searching for the most valuable data and critical systems before launching the main attack.

Think about that last point for a moment. The attackers aren't just after money in a bank account; they're betting that the organisation's duty of care will make them more likely to pay to stop the harm to patients.

DORA Article 5 DORA Article 5 requires financial entities (and by analogy, critical service providers) to establish a full ICT risk management framework. For a health platform, this means having a documented process to identify, classify, and mitigate threats like credential phishing long before they lead to a system-wide encryption event.

ISO A.5.24 ISO 27001 A.5.24 mandates planning and preparation for information security incidents. The confusion and delay Dr. Sharma's team experienced highlights a gap in such preparation—there was no clear, immediate action plan for staff when a widespread system compromise was detected.



Content Section 2: The Attack Anatomy: From Phish to Encryption

Understanding the step-by-step flow of the attack reveals why it's so effective. Let me show you exactly how Mediamap was compromised, moving from one employee's inbox to the encryption of the entire platform.

The Kill Chain

Step 1: Delivery. A well-crafted phishing email arrives in the inbox of a Mediamap finance officer. It appears to be an invoice from a known medical supplier, with a link to 'view details'.

Step 2: Exploitation. The officer clicks the link. The website looks legitimate but contains code that exploits a vulnerability in their web browser, silently installing a small piece of malware.

Step 3: Installation & Command. The malware, a remote access trojan (RAT), establishes a connection to the attacker's server. They now have a remote control session on a computer inside the Mediamap network.

Step 4: Lateral Movement. Using tools already present on the system and stolen credentials, the attackers move from the finance workstation to other servers. They focus on finding domain administrators—keys to the entire network kingdom.

Step 5: Exfiltration & Impact. Once domain admin rights are obtained, they identify and copy databases containing patient records to an external server. Then, they deploy ransomware to encrypt the primary servers and backup systems, triggering the outage Dr. Sharma witnessed.

Key Technical Enablers

The attackers used 'living-off-the-land' techniques. This means they used legitimate IT administration tools (like PowerShell or Remote Desktop Protocol) already installed on the network to do their malicious work. This makes them very hard to distinguish from normal admin activity.

They also employed credential dumping. After gaining initial access, they used software to extract usernames and password hashes from the computer's memory, which were then cracked or used in 'pass-the-hash' attacks to gain higher privileges without ever knowing the actual plaintext password.

Why Traditional Perimeter Defences Failed

Defensive MethodHow It Was BypassedTime to Bypass
Network FirewallAttack originated from a legitimate internal workstation after phishingMinutes (from click)
Antivirus SoftwareMalware was custom or used fileless techniques living in memorySeconds
Email Spam FiltersPhishing email was highly targeted (spear-phishing) and novelImmediate delivery
Network SegmentationLateral movement used valid admin credentials to access all segmentsHours to days

Notice what all of these methods have in common. The attack didn't break the walls; it tricked someone into opening a gate, then wore a stolen uniform to walk everywhere inside.

Mediamap likely had standard security measures. Here’s how the attack bypassed them:

Now pay attention, because this is the moment that defines the attack's success. The compromise of the domain administrator account. This is the moment where the attackers went from being a guest in one room to owning the keys to every door and safe in the building.

NIST PR.AC-1 NIST CSF PR.AC-1 (Protect - Identity Management and Access Control) requires managing identities and credentials. The attack succeeded because stolen, over-privileged credentials were not properly monitored or protected with multi-factor authentication, allowing unlimited lateral movement.

NIS2 Article 21 NIS2 Article 21 mandates security risk management measures. The failure to manage the risk of credential theft via phishing and the lack of controls to detect lateral movement with stolen credentials represent a direct shortfall against this requirement.



Content Section 3: Seeing the Unseen: Detection Before Encryption

Mediamap's systems likely knew something was wrong. They just couldn't tell anyone in a way that prompted action. The signals were there, buried in logs and network flows, waiting to be pieced together.

Network-Level Indicators

Unusual outbound connections: The initial malware would 'call home' to the attacker's command server. This connection would go to an IP address or domain name not associated with normal business. Research suggests monitoring for connections to newly registered domains or known malicious IPs.

Lateral movement patterns: A single workstation (the initially infected finance PC) making SMB or RDP connections to multiple other servers, especially domain controllers and database servers, in a short period. This 'hopping' behaviour is a major red flag.

Abnormal data volumes: In the exfiltration phase, large transfers of data from internal databases to an external IP address. This would create a noticeable spike in outbound traffic, often at unusual hours.

Endpoint-Level Indicators

Process anomalies: The use of PowerShell or the Windows Command Prompt to execute unusual, obfuscated commands or to download and run scripts from the internet. Legitimate admin use has patterns; malicious use often looks different.

Credential dumping activity: Security tools can detect when processes like 'lsass.exe' (which stores credentials) are accessed by unauthorised tools like Mimikatz. This is a near-certain sign of an attacker trying to steal passwords.

File system changes: The mass encryption of files by ransomware is preceded by the attacker placing the ransomware executable on multiple systems. Detection of the same unknown executable appearing on many machines is a late-stage but critical warning.

Identity Provider Signals

Impossible travel: A user account (like the compromised finance officer's) showing logins from two geographically distant locations in an impossibly short time.

Privilege escalation: Logs showing a standard user account being added to privileged groups like 'Domain Admins' or being granted excessive permissions on sensitive resources.

Abnormal login times: Successful logins for service or admin accounts occurring outside of normal business hours or maintenance windows, indicating an attacker using stolen credentials.

SOC2 CC7.1 SOC 2 CC7.1 requires detection and monitoring procedures to identify changes that introduce vulnerabilities. Monitoring for the specific indicators listed above—unusual network connections, credential dumping, and privilege escalation—is a direct application of this control to detect active intrusion, not just static vulnerabilities.

GDPR Article 32 GDPR Article 32 requires appropriate technical measures to ensure security of processing. Implementing detection for data exfiltration spikes and unauthorised access to personal data stores is a key technical measure to fulfil this obligation and potentially contain a breach before large-scale data loss occurs.


Activity: Threat Intelligence Indicator Mapping

This activity helps you translate the attack indicators from this lesson into a monitoring plan for your own environment. You will not need technical tools, just your knowledge and organisational understanding.

Important Security Note: Important Security Note: Do NOT document or share specific details about your organisation's network architecture, security tool configurations, or past security incidents. This is a high-level planning exercise. If you identify potential gaps, discuss them through proper internal channels with your security team.

Instructions

Step 1: Review the detection indicators listed in Content Section 3 (Network, Endpoint, Identity). For each category, note down which ones you are confident your organisation's security team currently monitors.

Step 2: Pick one indicator you are unsure about (e.g., 'detection of credential dumping tools' or 'monitoring for SMB lateral movement between servers'). Formulate a specific, non-technical question you could ask your security team to understand your coverage. Example: 'How do we detect if an attacker is using valid admin accounts to move between our clinical database server and our patient portal server?'

Step 3: Based on the attack flow, identify the single point you believe would be the most effective to detect the attack early. Is it the initial phishing email, the first malware call-home, or the first lateral movement attempt? Justify your choice in one sentence.

Step 4: Sketch a simple, hypothetical alert title and one-sentence description for that key detection point. For example: Alert: 'Multiple Failed Logins Followed by Success from New Geographic Region'. Description: 'This may indicate credential guessing followed by an attacker login.'

Submission

For the course discussion forum, share general learnings only:

  • Which category of indicators (Network, Endpoint, or Identity) seems to offer the best early warning, in your view?
  • What was the most challenging part of formulating a clear question for a security team?
  • Did mapping the attack steps change your perception of where defensive resources should be focused?

Do NOT share: Do NOT share your specific questions for your security team, details about your organisation's systems, or any assumptions about your organisation's security posture.

Review and comment on at least two other students' submissions, focusing on the rationale behind their chosen key detection point.


Content Section 4: Building Your Compliance Evidence

Compliance documentation is often seen as a box-ticking exercise. But in the wake of an attack like Mediamap's, it becomes the evidence of due diligence—or the record of missed steps. This lesson provides the raw material for that evidence.

Evidence Generation

This lesson provides documentation for multiple compliance frameworks:

For DORA Article 5 auditors... For DORA auditors, you can now demonstrate that key personnel have been trained on specific ICT risks relevant to health platforms, including the attack chain from phishing to ransomware, fulfilling part of the risk management framework requirement.

For ISO A.5.24 auditors... For ISO 27001 assessors, you can evidence that incident response preparation has been enhanced through training on the specific indicators of compromise (IoCs) associated with a major cyberattack scenario, directly supporting incident management planning.

For NIST DE.CM-8 auditors... For NIST CSF reviewers, you can show that your team's capability to detect malicious activity has been informed by understanding the specific detection methods for lateral movement and data exfiltration covered in this lesson.

Audit Trail

Document your completion of this lesson:

  • Lesson title and date completed
  • Time invested: approximately 45 minutes
  • Key learnings in your own words
  • Activity submission reference
  • Follow-up actions identified

Conclusion

Let me tell you how Dr. Sharma's story ended.

Mediamap's systems were down for 11 days. Patient appointments were cancelled, critical communications were lost, and the organisation faced significant regulatory scrutiny. Dr. Sharma and her team worked around the clock on manual processes, but the reputational damage was severe. The attackers had exfiltrated data before encrypting the systems, leading to a mandatory disclosure to regulators and affected patients.

The organisation eventually restored from offline, air-gapped backups the attackers hadn't found. They invested heavily in new security tools, but more importantly, they implemented mandatory phishing simulation training, strict multi-factor authentication for all admin accounts, and a 24/7 security operations centre to monitor for the exact indicators we've discussed.

But it doesn't have to be your story. That's why we're here.

You should now understand the dual motives behind attacks on health platforms. You understand the step-by-step kill chain from phishing to full encryption. You know the key technical indicators that can signal such an attack in progress. And you understand how this knowledge maps directly to your compliance and evidence-generation responsibilities.

Next, we'll explore Next, we'll explore Lesson 1.2: Building a Threat-Informed Defence. We'll take the intelligence from this attack and build a practical, layered defence strategy that addresses each stage of the kill chain.

See you there.


Key Takeaways

1. The Value of Health Data: Health platforms are prime targets not just for financial ransom but because the immutable personal data they hold and the critical services they provide create a powerful dual-pressure point for extortion.

2. The Attack Pathway: Catastrophic attacks often follow a predictable chain: initial phishing compromise, lateral movement using stolen credentials, privilege escalation to domain admin, followed by data theft and system-wide encryption.

3. Detection Beats Prevention: Since determined attackers will bypass perimeter defences, detection focused on internal behaviours—like lateral movement, credential dumping, and abnormal data flows—is critical for early identification and containment.

4. Intelligence Informs Compliance: Understanding specific real-world attack techniques provides the concrete evidence needed to demonstrate compliance with frameworks like DORA, NIST CSF, and GDPR, moving from abstract requirements to applied defence.


Resources

The course materials folder contains downloadable resources for this lesson:

  • Lesson 1.1 Quick Reference Card - Summarise the key detection indicators for a health platform cyberattack (phishing patterns, lateral movement signals, credential dumping, data exfiltration spikes) and immediate isolation/response steps on a single page.
  • Compliance Mapping Worksheet - Map your organisation's controls against the Mediamap attack kill chain to DORA Article 5, ISO 27001 A.5.24, NIST CSF PR.AC-1 & DE.CM-8, NIS2 Article 21, SOC 2 CC7.1, and GDPR Article 32.
  • Risk Assessment Template - Assess your organisation's specific exposure to health platform cyberattacks based on the phishing, credential theft, and lateral movement vectors covered in this lesson.
  • Further reading - Links to the NCSC guidance on mitigating malware and ransomware, the NIST Cybersecurity Framework details, and threat intelligence reports on healthcare sector attacks.

Cyber attack on health platform Mediamap - NZ Herald Defence Masterclass | Threat Intelligence | Lesson 1.1
© LimitedView Limited | 2026

This is 1 of 16 lessons included in the full package.

Enrol Now — Unlock All Lessons

Want to track your progress? Create a free account

Choose Your Access

All plans include 30-day money-back guarantee

Taster

£ 19

Single course access — ideal for trying us out

  • Full course access
  • Completion certificate
  • Try before you commit

Or get everything

Access every course in the catalogue, including all future courses

£ 29 /mo
Monthly All-Access

Every course, cancel anytime

£ 249 /yr
Annual All-Access

Save 28% — £20.75/month effective

Teams

Transparent pricing, no sales call required

Starter Team

£ 499 /year

£99.80/seat effective

Up to 5 learners, all courses included

Growth Team

£ 999 /year

£66.60/seat effective

Up to 15 learners, all courses included

Scale Team

£ 1999 /year

£39.98/seat effective

Up to 50 learners, all courses included

Need 50+ seats? Contact us for a custom plan.

Fast Checkout

Start Learning in Minutes

Enter your details, choose a tier, and complete secure checkout. Access starts immediately after payment confirmation.

  • Stripe-secured payment and delivery workflow
  • Audit-friendly completion records
  • Escalate to enterprise volume licensing at any point

48-Hour Relevance Guarantee

If this course does not provide at least five actionable controls your team can deploy quickly, request a full refund within 30 days.

Secure checkout

Select pricing tier

By continuing, you agree to the terms and privacy policy.

Not ready to purchase? Create a free account to browse and track progress.

Questions Before You Enrol?

Immediately after successful payment. Your learning link is generated and delivered in the success flow.
Yes. Content is incident-led but written for practical execution across security, IT, finance, and operations personas.
Yes. Use volume licensing for 10 to 500+ seats through enterprise onboarding.