CSIDB logo
Organisation

Smartpay

Profile

Primary URL
smartpay[.]co[.]nz
Location
New Zealand
Sector
Financial Services
Known incidents
1 incident
Updated
2026-09-01 03:18
Aliases
1 alias

Organisation tracking is available to eligible accounts.

Profile narrative

The organisation operates as an eftpos payment system operator, providing electronic funds transfer at point of sale services to retailers. Its core offerings include payment terminals that enable merchants to accept debit and card‑based transactions, and the backend transaction processing infrastructure that authorises and settles those payments. It serves the New Zealand market, where eftpos is a widely used payment method for everyday purchases. The company’s systems are designed to handle high volumes of point‑of‑sale transactions while maintaining continuous service availability. It does not collect or retain individual cardholder or payment card data as part of its operational model.

A distinguishing attribute of the operator is its deliberate decision not to store or collect sensitive payment card information, which reduces the risk of card data breaches. This design choice positions the organisation as a processor that focuses on facilitating the movement of funds rather than acting as a data repository for consumer financial details. The service is specialised in the eftpos network, which is distinct from international card schemes and relies on local banking infrastructure for settlement. By maintaining payment terminals and processing services that remain operational even during security incidents, the organisation demonstrates a commitment to service resilience for its merchant customers. Its sector positioning is that of a critical payments utility supporting retail commerce in New Zealand.

In June 2023 the organisation experienced a ransomware cyber incident that affected some of its New Zealand systems, prompting immediate containment actions and the engagement of cybersecurity specialists alongside government authorities. The attack resulted in the theft of information relating to a group of retailer customers, although the organisation confirmed that the stolen data did not include cardholder information. Payment terminals and transaction processing services continued to function normally throughout the event, and affected retailers were contacted directly by the company. The scope of the data theft and the exact number of impacted customers were still under investigation at the time of the initial reports. Ownership and parent‑subsidiary relationships of the organisation are not explicitly detailed in the publicly available sources consulted.

Incidents

1 incident linked to this organisation.

CSIDB