CSIDB logo
Incident

Paymark

Incident posture

Attack window
Jun 2023
Location
New Zealand
Status
Historical
CIA posture
Available to members
Updated
2026-08-29 03:18

Linked entities

Victim
Paymark
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jun 2023
Discovered
Jun 2023
Disclosed
Jun 2023
Resolved
Pending

Summary

Smartpay reported a ransomware cyber incident affecting some of its New Zealand systems, during which criminals stole information pertaining to a group of customers in New Zealand and Australia. The company said it does not collect or store individual cardholder data, so no payment card information was compromised. It took immediate containment steps, enlisted cybersecurity firm CyberCX, and worked with relevant government authorities. The incident prompted a drop in its share price and an ongoing investigation to determine the full extent of the data theft.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On 10 June 2023, SmartPay discovered a ransomware cyber incident affecting some of its systems in New Zealand. The company immediately took steps to contain the incident and engaged cybersecurity specialists CyberCX while also notifying relevant government authorities. SmartPay issued a statement to the NZX confirming the discovery and outlining its initial response. By 16 June 2023, the ongoing investigation confirmed that criminals had stolen information pertaining to a group of customers in both New Zealand and Australia from the affected New Zealand systems. SmartPay emphasized that understanding the full contents and extent of the stolen data was the highest priority of the investigation.

SmartPay stated that it does not collect or store individual cardholder information as part of its transaction processing, and therefore no card data was compromised in the attack. The company noted that its payment systems remained fully functional and that its customers, including retailers and hospitality businesses, could continue to use the EFTPOS terminals. Affected customers were to be contacted directly, although the total number of customers whose information was stolen was still being determined at the time of the statements. The affected customers were identified as retailers rather than individual shoppers.

SmartPay’s shares fell 3.88% to 7 cents following the news of the incident, later trading flat at $1.80. The incident was described as part of a renewed wave of cyber attacks that had previously targeted another local EFTPOS provider, Windcave, in March 2023, and the IT supplier to Fire and Emergency NZ. SmartPay processed more than 78 million transactions worth a total of $2.7 billion in the preceding year, underscoring the scale of its operations.

Sources

Sources available to members: 2 sources.

CSIDB