ChannelLife New Zealand - Industry insider news for technology resellers
New Zealand
Cybersecurity experts raise alarm after back-to-back data breaches

Cybersecurity experts raise alarm after back-to-back data breaches

Fri, 11th Sep 2026 (Today)
RNZ
RNZ

The education ministry says a data breach at an online learning platform may have included private information of students and teachers.

Mathspace confirmed last week that hackers had downloaded information on students, their parents or guardians, and school staff.

It comes as cybersecurity experts raise the alarm after back-to-back data breaches at two New Zealand companies, ZenTech and Thankyou Payroll.

In a special bulletin to school leaders, the ministry said the breach has impacted more than a million Mathspace users across New Zealand and Australia.

"We believe that the breach may have included private information, such as names and email addresses of students and teachers who have used the tool."

It says schools that have paid a subscription may be affected, as well as individuals who've signed up to the free version.

The ministry advised affected schools to review the Office of the Privacy Commissioner's guidance on privacy breaches.

"Each school is responsible for assessing its own circumstances and determining what actions are required under the Privacy Act 2020."

It advised schools and individuals to reset passwords and consult their IT administrators.

The ministry said Mathspace had alerted the Office of the Privacy Commissioner and the National Cyber Security Centre.

Likelihood of breaches increasing - expert

Police are investigating a breach at health research company Zenith Technology, also known as ZenTech, in which a large number of files related to clinical trials may have been stolen.

Soon after the ZenTech breach was made public, payroll company Thankyou Payroll notified its users that they had been exposed by a global security breach involving open source analytics tool Metabase.

Ben Van Der Weerd, an undergraduate cybersecurity researcher at Victoria University, said both companies made attractive targets.

"Payroll companies in specific, they have a lot of people on file, they have lot of 'PII' or 'personally identifiable information', and this data goes for a lot of money on the dark web and can enable quite a lot of further attacks and phishing," he explained.

"Now they know where you live and they've got your IRD number and full name, so they might say 'oh, you didn't pay enough tax on this pay rate exactly 3 months ago under this IRD number, log into the portal to pay your tax' and that would get quite a few people."

A company like ZenTech, on the other hand, had high-value data that could be used to negotiate for a ransom.

"Health companies as well, they're more likely to pay a ransom," he said.

"If you were hosting a website for your cafe, if you breach that there's not a lot of return for the hackers, but if you breach something that has a lot of people's biological data or financial records, that's going to get you somewhere."

The office of ZenTech - Zenith Technology in Dunedin.

Dr Abhinav Chopra, a cybersecurity expert at the University of Auckland, said even if a ransom couldn't be negotiated, the patient data would be valuable on the dark web, as it was fundamental personal information that couldn't be updated like a password or email address.

"They have information about their bodies and their allergies, they've got clinical information, which is information that cannot be changed, so the dataset is quite static and can be used by a number of buyers on the black market," Chopra said.

"So this is data that can get them good money either way, both from ransom or they sell the data on the black market."

He said the hackers who targeted ZenTech were previously known to use phishing.

"From what I've learned about the hackers, the last incident [they were involved in] they did some phishing to get the credentials of a person, and then logged into a privileged account and from there moved to get access to their dataset," he said.

"But I'm not saying that happened to ZenTech."

He said the attack was a reminder that cyber attacks were becoming more likely, even for relatively small companies.

"We have to be serious about the likelihood [of cyber attacks]. When you do your likelihood-cross-impact, impacts have been high but most of us have been saying, 'oh, well the likelihood is low'. But since the Waikato DHB, all those likelihoods have increased," he said.

"Many of the controls are pretty cheap to achieve, so just getting an assessment done and then getting onto the quick win kind of layers that you can adopt while you work on a roadmap of how you can get the different other layers into your mix is really helpful."

This story was originally published on RNZ.co.nz and is republished with permission.