CSIDB logo
Incident

Smartpay

Incident posture

Attack window
Jun 2023
Location
New Zealand
Status
Unknown
CIA posture
Available to members
Updated
2026-09-05 10:46

Linked entities

Victim
Smartpay
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Smartpay disclosed a ransomware cyber incident that affected some of its New Zealand systems, leading to the theft of information belonging to a group of customers in Australia and New Zealand while confirming that no cardholder data was compromised because it does not store such details. The company engaged cybersecurity specialists CyberCX, worked with relevant authorities, and took immediate containment steps, noting that its payment terminals remained operational for retailers and hospitality businesses. Affected customers are being contacted directly, and the firm said understanding the full scope of the stolen data is the top priority of its ongoing investigation.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On June 10, 2023, SmartPay discovered a ransomware cyber incident affecting some of its systems in New Zealand and immediately began investigating the event. The company reported that it had taken immediate steps to contain the incident and had engaged the cybersecurity firm CyberCX, while also working with relevant government authorities. By June 16, 2023, SmartPay’s ongoing investigation confirmed that criminals had stolen information pertaining to a group of customers in both Australia and New Zealand from its New Zealand systems. SmartPay emphasized that the stolen data did not include individual cardholder information, as it does not collect or store such details as part of its transaction processing. The company stated that its payment systems remained fully functional and that retailers and hospitality businesses could continue to use its EFTPOS terminals without interruption. SmartPay noted that it would directly contact any customers whose data had been compromised and that no action was required from unaffected customers. Following the disclosure, SmartPay’s shares fell 3.88% to seven cents on the NZX, later trading flat at $1.80.

SmartPay processed more than seventy‑eight million transactions worth a total of $2.7 billion in the previous year, underscoring the scale of its operations. The incident is situated within a renewed wave of cyber attacks that has also targeted another local EFTPOS provider, Windcave, in March 2023, and the IT supplier to Fire and Emergency New Zealand. SmartPay’s spokesman said the firm could not comment on the ransom amount demanded or whether any negotiations were taking place, and the exact number of affected customers remained under determination. The affected customers were identified as retailers rather than individual shoppers. In its statements, SmartPay reiterated that understanding the full contents and extent of the stolen data remained the highest priority of its investigation. The company also noted that New Zealand’s Budget 2023 did not follow the cybersecurity funding measures included in Australia’s Budget 2023, which had allocated significant resources to initiatives such as a National Anti‑Scam Centre and a Cyber Security Co‑ordinator. SmartPay concluded that it would continue to prioritize the safety and security of its systems and services while working with experts and authorities to resolve the incident.

Sources

Sources available to members: 2 sources.

CSIDB