Three breaches, one week, one lesson
New Zealand had a bad cyber week. Police are investigating a breach at Dunedin clinical trials company Zenith Technology, where a ransomware group claims to have stolen sensitive health files, with Health Minister Simeon Brown briefed. Almost simultaneously, payroll company Thankyou Payroll notified its users they had been caught up in a global security breach exposing IRD numbers, home addresses and bank details. A third incident at online learning platform Mathspace hit more than a million users across New Zealand and Australia.
The common thread matters more than any single incident. Cyber risk has quietly moved from an IT inconvenience to a core business liability, and the payroll breach is the one that should have every board paying attention.
The vulnerability came in through the back door
The Thankyou Payroll breach was not a direct attack on Thankyou Payroll. It came through Metabase, an open-source analytics tool the company used, which disclosed a critical vulnerability in August allowing attackers to inject SQL and gain administrator access. Metabase urged users to patch immediately. That patch did not happen in time.
“We know our customers trust us with important information and we apologise for the concern and disruption this incident may cause,” Thankyou Payroll said. This is the supply chain attack in practice. A flaw in one third-party tool reaches every organisation that tool touches.
Why payroll data is worth so much
Ben Van Der Weerd, a cybersecurity researcher at Victoria University, was blunt about the appeal. Payroll companies “have a lot of people on file, they have a lot of ‘PII’ or ‘personally identifiable information’, and this data goes for a lot of money on the dark web and can enable quite a lot of further attacks and phishing,” he told RNZ.
He spelled out the downstream risk. With your IRD number, full name and address, an attacker “might say ‘oh, you didn’t pay enough tax on this pay rate exactly 3 months ago under this IRD number, log into the portal to pay your tax’ and that would get quite a few people,” Van Der Weerd said. The exact dataset exposed at Thankyou Payroll is what you need to build convincing, targeted scams against every affected employee.
The legal trap employers are sitting in
Here is the part most coverage misses. Under the Privacy Act 2020, the principal organisation remains legally responsible for personal data held by a contractor. Outsourcing your payroll does not outsource your obligation to protect staff data.
Worse, the 72-hour notification clock starts when the contractor becomes aware of a breach, not when it tells you. By the time Thankyou Payroll notified its clients, those clients may already have been running against their own legal deadline without knowing it existed.
Privacy Commissioner Michael Webster frames this as a board-level issue. “Privacy breaches are bad for business. At the very least, your reputation takes a hit. They can also lead to a loss of clients and money,” he wrote for the Institute of Directors. His survey found 66% of respondents would consider changing providers over poor privacy and security practices. For a payroll firm, that is existential.
The numbers say this is now a when, not an if
The Kordia NZ Business Cyber Report 2026 found 44% of large NZ businesses suffered a successful cyber-attack in the past 12 months, with 61% of those attacks causing costly business impacts and financial extortion rising to 19% of attacks. NCSC data cited in the report shows NZ$12.4 million in direct losses in a single quarter, a 118% jump.
Most alarming for smaller firms, 70% of uninsured SMEs that received a ransom letter would not survive into the following year. Grant Thornton put more than 35% of breaches as involving third parties, and did not mince words on the cause. The spate of attacks “reflects New Zealand’s track record of cybersecurity underinvestment and lack of regulation” that has made the country “an appealing target,” the firm wrote.
What a board should be asking now
Dr Abhinav Chopra, a cybersecurity expert at the University of Auckland, argues the risk calculus has changed. Impact was always high, but “since the Waikato DHB, all those likelihoods have increased,” he told RNZ. The good news is that many controls are cheap. “Just getting an assessment done and then getting onto the quick win kind of layers” delivers real protection, Chopra said.
The practical questions are not complicated. Is your payroll provider ISO 27001 certified? How fast will they tell you if something breaks, and does your response plan assume they might be late? Does your cyber insurance actually cover a third-party vendor breach, or is there a gap? And how quickly does every vendor holding your staff data apply critical patches, given a missed Metabase update is what started all of this? The employers who cannot answer those questions are pricing in a risk they have not even measured yet.
Sources
- Cybersecurity experts raise alarm after back-to-back data breaches (2026-09-11)
- New Zealand payroll firm apologises after being caught up in data breach (2026-09-10)
- Fears sensitive health files stolen in cyber incident, minister briefed (2026-09-10)
- Sensitive files stolen from Dunedin health tech firm in ‘major’ data breach (2026-09-10)
- New Zealand Business Cyber Security Report 2026 (2026-03)
- NZ’s cyber wake-up call: Is your business at risk? (Yes, it is) (2026-03-30)
- Large privacy breaches impact us all (2026-06-12)
- Ransomware group claims cyberattack on Dunedin clinical trial company (2026-09-10)
Join the discussion
Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.