Smartpay
Incident posture
Timeline
Summary
Smartpay disclosed a ransomware cyber incident that affected some of its New Zealand systems and led to the theft of information belonging to a group of customers in New Zealand and Australia. The company said it does not store cardholder data, so no payment card information was compromised, and it engaged cybersecurity specialists CyberCX and worked with authorities to contain the breach. The company’s payment terminals remained operational for retailers, its shares fell after the announcement, and it is directly contacting affected customers while investigating the scope of the data theft.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Saturday, 10 June 2023, Smartpay discovered that it was experiencing a ransomware cyber incident affecting some of its systems in New Zealand and immediately began containment efforts. The company engaged the cybersecurity firm CyberCX and notified relevant government authorities as part of its response. By Friday, 16 June 2023, the ongoing investigation confirmed that criminals had stolen information pertaining to a group of customers in Australia and New Zealand from the compromised New Zealand systems. Smartpay emphasized that it does not collect or store individual cardholder information, so no payment card data was compromised in the incident. Despite the breach, the company stated that its eftpos payment systems remained fully functional and that retailers and hospitality businesses could continue to use the terminals. Market reactions were mixed, with one report noting that Smartpay’s shares fell 3.88 percent to 7 cents following the announcement, while another source reported that the shares were flat at $1.80 in late trading.
Smartpay said it was directly contacting the customers whose data had been affected, although the exact number of impacted retailers was still being determined at the time of the statements. The stolen information did not include card details, but the company described understanding the full contents and extent of the data theft as the highest priority of its investigation. The incident is situated within a broader trend of cyber attacks targeting New Zealand payment providers, following a March ransomware event against another eftpos operator, Windcave, and a separate breach affecting the IT supplier to Fire and Emergency NZ. In response to the growing threat, Justice Minister Kiri Allan reiterated that the government would not make it illegal to pay a ransomware demand, arguing that such a measure would criminalise victims. Budgetary comparisons showed that New Zealand’s 2023 budget did not mirror the cybersecurity allocations in Australia’s 2023 budget, which included A$2 billion for digital initiatives, A$86.5 million for a National Anti‑Scam Centre, A$46.5 million for a Cyber Security Co‑ordinator, and a A$131 million increase for the office of the e‑Safety Commissioner. Meanwhile, Netsafe in New Zealand received a one‑off $690 000 funding boost, bringing its total annual funding to approximately $4.5 million. Smartpay’s representatives declined to disclose any ransom amount demanded or indicate whether negotiations with the attackers were underway.
Sources
Sources available to members: 2 sources.