CSIDB logo
Incident

ManageMyHealth

Incident posture

Attack window
Dec 2025
Location
New Zealand
Status
Resolved
CIA posture
Available to members
Updated
2026-09-16 19:12

Linked entities

Victim
ManageMyHealth
Threat actors
1 actor
Sources
4 sources

Timeline

Occurred
Undetermined
Discovered
Dec 2025
Disclosed
Jan 2026
Resolved
Jan 2026

Summary

ManageMyHealth experienced a breach when attackers accessed its patient portal and exfiltrated tens of gigabytes of health data affecting roughly six to seven percent of its user base. The intrusion was discovered after users noticed service disruptions and learned of the incident through social media and news reports rather than direct notification. The company subsequently shut down its mobile app, engaged forensic experts, and obtained a court order to limit further dissemination of the stolen information. While asserting that the environment is now secure, the company apologized for the distress caused and cooperated with a government‑ordered review of its security practices.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On December 30 2025 ManageMyHealth detected a cyber‑attack and was notified that the ransomware group Kazu had breached its systems and exfiltrated approximately 108 gigabytes of patient data. The attackers gained entry through a valid user password, describing the intrusion as coming “in through the front door” and penetrating a single system module that contained health documents from specialist referrals. Kazu claimed to have taken more than 420 000 records or files and demanded a ransom of US $60 000 (approximately AU $89 230) with a threat to publish the data if payment was not made by January 15 2026. ManageMyHealth stated that the breach resulted from broken access controls and delayed detection, and that it had contained the incident and secured its platform. The company turned off its mobile app, advised users not to communicate with Kazu, and obtained a High Court injunction barring third parties from accessing any leaked data.

In the days following the breach ManageMyHealth began notifying general practices on January 5 2026, providing each practice with a confidential list of affected patients through its secure Provider Portal and guidance on handling patient inquiries. Direct patient notification was planned to start later that week once all general practices had been informed, with coordination required among Health New Zealand, General Practice New Zealand and individual practices to avoid duplicate or confusing messages. A dedicated 0800 helpline was established for affected patients, with further details to be shared in a subsequent update. The company apologized for the pain and anxiety caused to providers and patients, acknowledging that communication could have been improved while emphasizing that its priority had been securing patient data and verifying information before release.

According to ManageMyHealth’s first statement on January 1 2026, between six and seven percent of its approximately 1.8 million New Zealand patients could have been compromised, which the source describes as representing between 100 000 and 1 200 000 individuals. The breach affected medical and personal data, and the company reported that it had signed up 1.85 million patients globally since 2008, operating from offices in Auckland, Melbourne and Chennai. New Zealand Minister of Health Simeon Brown described the incident as “incredibly concerning,” announced a government review to examine the cause, existing data protections and third‑party access to health data, and stated that the error lay with ManageMyHealth. He noted that, under New Zealand privacy legislation, potential fines for proven fault could reach NZ $10 000 (approximately AU $8 600), contrasting with possible Australian penalties of up to AU $50 million or 30 percent of turnover. The minister urged the company to apologize to all affected users, which ManageMyHealth did in its latest statement. The trans‑Tasman provider now faces an official probe into the breach, and the company confirmed it is working with Health New Zealand, the New Zealand Police, other government agencies and independent international forensic consultants to respond to the incident.

Sources

Sources available to members: 4 sources.

CSIDB