CSIDB logo
Incident

Australia and New Zealand Banking Group (New Zealand)

Incident posture

Attack window
Sep 2021
Location
New Zealand
Status
Historical
CIA posture
Available to members
Updated
2025-10-23 00:00

Linked entities

Victim
Australia and New Zealand Banking Group (New Zealand)
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

ANZ New Zealand experienced a significant disruption to its online banking services due to a distributed denial of service (DDoS) attack, which temporarily rendered its internet banking app and website inaccessible. The incident impacted multiple other New Zealand organizations, including Kiwibank, MetService, New Zealand Post, and Inland Revenue, with the country's cybersecurity agency Cert NZ confirming the coordinated attacks and assisting affected parties. While most services across impacted entities were restored relatively quickly, the bank's online channels remained offline for an extended period before full resolution, though core transactional services such as ATMs, card payments, and automated transfers continued functioning normally throughout the outage.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 7, 2021, ANZ New Zealand experienced a widespread outage of its internet banking app and website due to a distributed denial-of-service (DDoS) attack. The incident disrupted customer access to online banking services, though ATM transactions, Eftpos, card payments, automatic payments, bill payments, and direct debits remained operational. New Zealand’s cybersecurity agency, Cert NZ, confirmed multiple organizations were simultaneously targeted by the same DDoS campaign, including Kiwibank, MetService, New Zealand Post, and Inland Revenue. ANZ acknowledged the outage publicly via social media, stating all available resources were dedicated to restoring services. By the morning of September 8, most other affected organizations had recovered, but ANZ’s systems remained offline, extending the disruption for its customers into a second day.

ANZ resolved the outage by 2:27 PM AEST on September 8, 2021, restoring full access to its digital platforms. The bank thanked customers for their patience in a public tweet following service restoration. Cert NZ had actively monitored the attacks and collaborated with impacted entities throughout the incident. The DDoS attack mirrored a 2020 incident against the New Zealand Stock Exchange (NZX), which suffered a week-long outage from similar attacks attributed to a criminal group targeting global financial institutions with extortion demands. No explicit ransom demands or threat actor attributions were disclosed in ANZ’s case. The incident highlighted recurring DDoS vulnerabilities in New Zealand’s critical financial infrastructure, though ANZ’s core transaction systems avoided compromise, limiting direct financial harm to customers.

Sources

Sources available to members: 1 source.

CSIDB