CSIDB logo
Incident

Eftpos

Incident posture

Attack window
Jun 2023
Location
New Zealand
Status
Historical
CIA posture
Available to members
Updated
2026-09-10 05:29

Linked entities

Victim
Eftpos
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jun 2023
Discovered
Jun 2023
Disclosed
Jun 2023
Resolved
Pending

Summary

Smartpay discovered a ransomware cyber incident affecting some of its New Zealand systems, leading to the theft of customer information from retailers in Australia and New Zealand while confirming that no cardholder data was compromised and its payment terminals remained operational. The company engaged cybersecurity specialists CyberCX, collaborated with government authorities, and began contacting affected customers as it works to determine the full scope of the data theft, a process that contributed to a decline in its share price.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On June 10 2023 Smartpay discovered a ransomware cyber incident affecting some of its New Zealand systems. Immediate steps were taken to contain the incident. Cybersecurity specialists CyberCX were engaged. Relevant government authorities were notified. The company stated that its payment systems remained fully functional. Retailers and hospitality businesses could continue to use the eftpos terminals.

By June 16 2023 the investigation confirmed that criminals had stolen information pertaining to a group of customers in Australia and New Zealand from the affected New Zealand systems. Smartpay emphasized that it does not collect or store individual cardholder information. Therefore no card data was compromised. The number of affected customers was still being determined. The company said it would contact those directly. The incident caused Smartpay’s shares to fall 3.88% to 7c on the news. Later trading showed the shares flat at $1.80.

The attack was described as part of a renewed wave of cyber incidents that had previously included a March ransomware attack on another local eftpos provider Windcave. It also included an intrusion against the IT supplier to Fire and Emergency NZ. Justice Minister Kiri Allan reiterated her position that making it illegal to pay a ransomware demand would criminalise victims. New Zealand’s Budget 2023 did not mirror the cybersecurity funding increases seen in Australia’s Budget 2023. Australia’s Budget 2023 allocated A$2 billion for digital initiatives. It also allocated A$86.5 million for a National Anti‑Scam Centre. A$46.5 million was earmarked for a Cyber Security Coordinator role. A$131 million was provided to boost the e‑Safety Commissioner’s office. Netsafe received a one‑off $690 000 increase, bringing its total funding to around $4.5 million.

Smartpay said understanding the contents and extent of the stolen data remained the highest priority of its investigation. A spokesman noted that the firm could not disclose any ransom amount demanded or whether negotiations were underway. The affected customers were identified as retailers rather than individual shoppers. The company continued to work with CyberCX and government authorities to secure its systems. It also aimed to prevent further unauthorized access.

Sources

Sources available to members: 2 sources.

CSIDB