Smartpay
Incident posture
Timeline
Summary
Smartpay reported a ransomware cyber incident affecting some of its New Zealand systems, prompting immediate containment measures and the engagement of cybersecurity specialists CyberCX alongside government authorities. The investigation confirmed that criminals had stolen information relating to a group of customers in Australia and New Zealand, although no cardholder data was compromised because the firm does not collect or store such details. Affected customers, primarily retailers, are being contacted directly while payment terminals remain operational. The company’s shares fell following the disclosure, reflecting market concern over the breach.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 10, 2023, Smartpay discovered a ransomware cyber incident affecting some of its systems in New Zealand. The company immediately took steps to contain the incident and engaged cybersecurity specialists CyberCX, while also notifying relevant government authorities. Smartpay issued a statement to the NZX confirming the discovery and describing the immediate response actions.
The investigation revealed that criminals had stolen information relating to a group of customers in both New Zealand and Australia from Smartpay's New Zealand systems. Smartpay emphasized that it does not collect or store individual cardholder information, so no card data was compromised, and its payment systems remained fully functional for retailers and hospitality businesses. The company began directly contacting affected customers, noting that the affected parties were retailers rather than individual shoppers. Smartpay reported processing over 78 million transactions worth $2.7 billion in the previous year. Following the news, Smartpay's shares dropped 3.88% to 7c according to the NZX statement, while later trading showed shares flat at $1.80.
By June 16, 2023, the ongoing investigation confirmed the theft of customer information and identified understanding the contents and extent of that data as the highest priority. Smartpay stated that the number of affected customers was still being determined and that it could not comment on any ransom amount demanded or negotiations. The incident was described as part of a renewed wave of cyber attacks that had previously targeted another local eftpos provider, Windcave, in March, and the IT supplier to Fire and Emergency NZ. Smartpay continued to prioritize the safety and security of its systems and services while working with CyberCX and government authorities.
Sources
Sources available to members: 2 sources.