CSIDB logo
Incident

Smartpay

Incident posture

Attack window
Jun 2023
Location
New Zealand
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 04:30

Linked entities

Victim
Smartpay
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Smartpay, a New Zealand-listed eftpos payment system operator, experienced a ransomware cyber incident affecting some of its systems, prompting the company to engage cybersecurity specialists CyberCX and work with relevant government authorities. While the attack led to the theft of customer information belonging to a group of retailers and hospitality businesses in Australia and New Zealand, no individual cardholder or payment data was compromised, as the company does not collect or store such information during transaction processing. Affected business customers were being contacted individually, and eftpos terminals remained fully functional for continued use by retailers and hospitality operators. The incident was part of a broader wave of cyber attacks targeting New Zealand firms, including a previous attack on another eftpos provider, and contributed to a notable share price drop as the investigation into the scope of the data theft continued.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On Saturday, 10 June 2023, Smartpay, an NZX-listed eftpos payment system operator with customers in New Zealand and Australia, discovered that it was experiencing a ransomware cyber incident affecting some of its systems in New Zealand. In response, the company took immediate steps to contain the incident, engaged cybersecurity specialists CyberCX, and began working with relevant government authorities. The discovery was communicated to the market through a statement to the NZX stock exchange on the same day, and the company's shares fell 3.88% to 7c on the news. As an initial response, Smartpay confirmed that its eftpos terminals remained operational and that retailers and hospitality businesses could continue using them without interruption. The company also emphasised that it did not collect or store individual cardholder information or details as part of its transaction processing.

On Friday, 16 June 2023, Smartpay's ongoing investigation confirmed that criminals had stolen information pertaining to a group of customers in Australia and New Zealand from its New Zealand systems. The company stated that understanding the contents and extent of that data theft was now the highest priority of its investigation. A Smartpay spokesman indicated that the affected customers were retailers rather than shoppers, and that the firm could not comment on the ransom amount demanded or whether any negotiations were taking place. The number of customers affected was still being determined at the time of reporting. Smartpay confirmed it would directly contact those customers whose other data had been compromised, while reiterating that no card data had been compromised and that its payment systems remained fully functional.

The incident formed part of a renewed wave of cyber attacks in New Zealand, which had included the March attack on another local eftpos provider, Windcave, as well as an attack on an IT supplier to Fire and Emergency NZ. In the broader policy context, Justice Minister Kiri Allan had, just a month prior, again ruled out making it illegal to pay a ransomware demand, stating that such a move would criminalise victims. New Zealand's Budget 2023 did not follow cybersecurity-related moves seen in Australia's Budget 2023, which included significant funding for new digital initiatives tied to e-safety, a National Anti-Scam Centre, and a Co-ordinator for Cyber Security. Smartpay processed more than 78 million transactions worth a total of $2.7 billion in the preceding year, underscoring the scale of the business impacted by the attack.

Sources

Sources available to members: 2 sources.

CSIDB