CSIDB logo
Incident

Smartpay

Incident posture

Attack window
Jun 2023
Location
New Zealand
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 02:28

Linked entities

Victim
Smartpay
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware cyber incident affected some systems in New Zealand belonging to the eftpos payment system operator, prompting immediate containment steps and engagement of cybersecurity specialists alongside relevant government authorities. The company confirmed that criminals had stolen information pertaining to a group of retailer customers from its New Zealand systems, while clarifying that no individual cardholder or payment card data was compromised since it does not collect or store such details. Payment terminals and transaction processing services remained fully functional throughout, with affected retailers being contacted directly. The scope of the data theft and the number of impacted customers were still under investigation at the time of reporting.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On Saturday, 10 June 2023, Smartpay, an NZX-listed eftpos payment system operator, discovered that it was experiencing a ransomware cyber incident affecting some of its systems in New Zealand. In response, the company took immediate steps to contain the incident, engaged cybersecurity specialists CyberCX, and began working with the relevant government authorities. Smartpay communicated details of the event to the New Zealand Stock Exchange through an official statement, alerting the market to the developing situation. The incident occurred against the backdrop of a renewed wave of cyber attacks in New Zealand, which had already included a March 2023 attack on another local eftpos provider, Windcave, as well as a separate attack on an IT supplier to Fire and Emergency New Zealand.

Following the initial discovery, Smartpay's ongoing investigation confirmed on Friday, 16 June 2023, that criminals had stolen information pertaining to a group of customers in Australia and New Zealand from Smartpay's New Zealand systems. The company emphasised that it did not collect or hold individual cardholder information as part of its transaction processing, and no card data was compromised in the attack. The stolen information pertained to customers of Smartpay, specifically retailers rather than individual shoppers using eftpos terminals. A Smartpay spokesman indicated that the affected customers were being directly contacted by the firm, though the specific number of customers affected remained under determination at the time of reporting. The spokesman also declined to comment on any ransom amount demanded by the attackers or whether negotiations were taking place. Understanding the contents and extent of the data theft was described as the highest priority of the company's investigation.

The impact on Smartpay's core payment services was limited, with eftpos terminals continuing to function for retailers and hospitality businesses throughout the incident. Smartpay processed more than 78 million transactions worth a total of $2.7 billion in the preceding year, and the company reassured the market that its payment systems remained fully operational despite the breach. Following the initial announcement, Smartpay's shares dropped 3.88% to 7c on the NZX, although by later reporting they were flat at $1.80 in late trading. The company continued to prioritise the safety and security of its systems and services to its customers as the response progressed. Customers were advised that there was nothing they needed to do, with those whose data was compromised being contacted directly by Smartpay.

The broader regulatory and policy context surrounding the incident included ongoing debates in New Zealand about how to handle ransomware demands. Earlier in 2023, Justice Minister Kiri Allan had ruled out making it illegal to pay a ransomware demand, arguing that such a move would criminalise victims. Some industry players viewed making ransom payments illegal as a potential circuit-breaker against the rising tide of attacks. New Zealand's Budget 2023 did not follow cybersecurity initiatives seen in Australia's Budget 2023, which allocated A$2 billion for new digital initiatives including a National Anti-Scam Centre, an SMS Sender ID Registry, and a Co-ordinator for Cyber Security. Domestically, Netsafe received a one-off increase of $690,000, bringing its total funding to approximately $4.5m. The Smartpay incident underscored the disruptive nature of ransomware attacks, which can cause economic damage, expose individuals' information, and pose risks to critical services, though in this instance the operational disruption was contained while the data theft remained the central concern for the affected retailer customers in Australia and New Zealand.

Sources

Sources available to members: 2 sources.

CSIDB