CSIDB logo
Incident

Smartpay

Incident posture

Attack window
Jun 2023
Location
New Zealand
Status
Historical
CIA posture
Available to members
Updated
2026-09-10 05:11

Linked entities

Victim
Smartpay
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jun 2023
Discovered
Jun 2023
Disclosed
Jun 2023
Resolved
Pending

Summary

Smartpay discovered a ransomware cyber incident affecting some of its systems in New Zealand, leading to the theft of information pertaining to a group of customers in Australia and New Zealand while cardholder data remained uncompromised and payment services continued to operate. The company took immediate containment steps, engaged cybersecurity specialists CyberCX, and collaborated with relevant government authorities as it worked to determine the full scope of the data breach. Share prices fell following the disclosure, reflecting market concern over the incident's potential impact.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On June 10, 2023, Smartpay discovered a ransomware cyber incident affecting some of its systems in New Zealand. The company stated that criminals had stolen information relating to a group of customers in New Zealand and Australia. Smartpay confirmed that the breach did not involve cardholder data because it does not collect or store individual card information as part of its transaction processing. The affected customers were identified as retailers rather than individual shoppers. The company noted that its payment systems remained fully functional and that eftpos terminals could continue to be used by customers.

In response to the incident, Smartpay took immediate steps to contain the breach and engaged cybersecurity specialists from CyberCX. The company also notified relevant government authorities and began an ongoing investigation to understand the contents and extent of the stolen data. By June 16, 2023, the investigation had confirmed that criminals had stolen information pertaining to a group of customers in Australia and New Zealand from Smartpay’s New Zealand systems. Smartpay said that understanding the full scope of the data theft was the highest priority of its investigation. The firm indicated that it was directly contacting customers whose data had been compromised.

Smartpay’s shares reacted to the news, dropping 3.88 percent to 7 cents on the NZX following the initial announcement, and later trading flat at $1.80 per share. The company emphasized that no card data was compromised and that its core payment processing continued without interruption. Smartpay processed more than 78 million transactions worth a total of $2.7 billion in the previous year. The incident was described as part of a renewed wave of cyber attacks that had previously targeted another local eftpos provider, Windcave, and the IT supplier to Fire and Emergency NZ. A spokesman for Smartpay said the firm could not comment on any ransom demand or negotiations, and the number of affected customers was still being determined at the time of reporting.

Sources

Sources available to members: 2 sources.

CSIDB