3 NZ Cyber Breaches in 1 Week: What Every NZ Business Should Do | NSP

NSP Marketing

14 September 2026

10 min

Read

Three NZ Breaches in One Week. What Every Business Should Do Next.

 

In the space of a few days in the last week, three separate organisations with New Zealand connections confirmed significant data breaches.

On 7 September 2026, Mathspace - an online mathematics platform used in schools across Australia and New Zealand - confirmed that 1,079,819 students, parents, teachers, and staff had been affected by unauthorised access to its internal reporting system. The geographic scope was limited to Australia and New Zealand. That number makes it one of the largest single-vendor education data exposures reported in the Asia-Pacific region this year.

On 10 September, Dunedin-based clinical research organisation Zenith Technology (ZenTech) confirmed it was responding to a cyber security incident in which a large number of files relating to clinical trials may have been stolen. A ransomware group claimed responsibility. Health Minister Simeon Brown was briefed. Police are investigating. Health New Zealand confirmed it became aware of the incident after files attributed to ZenTech were identified online, with some already published.

The same day, Thankyou Payroll - a NZ payroll company servicing a number of charities - notified customers that they had been caught in a global security breach involving a third-party analytics tool called Metabase. Information accessed included names, IRD numbers, email and physical addresses, bank account details, and payment histories.

Three organisations. Three different sectors. Three different attack pathways. All in one week.

RNZ noted that the last time New Zealand saw this concentration of significant breaches was when ManageMyHealth, MediMap, and IntraCare were all hit in the space of a few months earlier in 2026 - described at the time as comparable in scale to the 2021 Waikato DHB breach, which was called one of the worst incidents in New Zealand's history.

Cybersecurity experts quoted this week described the pattern plainly. Ben Van Der Weerd from Victoria University: "Payroll companies have a lot of people on file, a lot of personally identifiable information, and this data goes for a lot of money on the dark web." Dr Abhinav Chopra from the University of Auckland, on clinical health data: "They have information about their bodies and their allergies, they've got clinical information, which is information that cannot be changed - the dataset is quite static and can be used by a number of buyers on the black market."

This is not a coincidence. It's a pattern. And it raises a direct question for every business leader in New Zealand who hasn't reviewed their security posture recently: if these three organisations were targeted, what does your environment look like to the same attackers?

 

What Each Breach Tells Us

These three incidents aren't just news items. Each one contains a specific lesson about how breaches happen - and how they could happen to a business that looks very different from a clinical research lab or a payroll company.

ZenTech: The Ransomware Pattern Is Still Running

The ZenTech breach followed a now-familiar sequence. A ransomware group identified the organisation as a target, gained access, exfiltrated data, and published samples online before publicly claiming responsibility and issuing a deadline to negotiate. The NCSC had published supply chain security guidance on 4 August 2026 - 37 days before the ZenTech incident became public - citing a pattern of third-party supplier incidents earlier in 2026.

ZenTech worked with Health New Zealand and held clinical trial data for pharmaceutical research. The sensitivity of that data - health information from trial participants that is, as Dr Chopra noted, static and permanently valuable - makes it particularly attractive to ransomware groups who know it creates significant pressure to pay.

The lesson for other businesses: the sensitivity and uniqueness of your data determines how attractive you are as a target. Businesses that handle health information, legal records, financial data, or other information that can't simply be changed after a breach face higher extortion pressure than those handling more generic data. Ransomware groups assess this before they act.

What would this look like in your business? If a ransomware group got into your environment today, what data would give them the most leverage? Do you know where that data is, who can access it, and whether your backups are isolated and tested?

Thankyou Payroll: Third-Party Risk Is Your Risk Too

Thankyou Payroll's own systems weren't breached. A third-party analytics tool called Metabase - which Thankyou Payroll used and which many other organisations worldwide also use - was compromised in a global incident. The payroll company's customer data was in that tool. The payroll company's customers are now dealing with the consequences.

This is the supply chain risk that the NCSC specifically called out in its August 2026 guidance: "This sensitive data is attractive to cyber criminals as it can be used to extort the companies responsible or the individuals concerned, and third party suppliers may be considered an easier target if adequate cyber security controls have not been implemented."

The data accessed - names, IRD numbers, bank account details, payment histories - enables exactly the kind of downstream fraud that security researcher Ben Van Der Weerd described: "Now they know where you live and they've got your IRD number and full name, so they might say 'oh, you didn't pay enough tax on this pay rate exactly three months ago under this IRD number, log into the portal to pay your tax.'" That's a realistic phishing scenario built from the breach data itself.

What would this look like in your business? How many third-party tools - analytics, reporting, automation, AI tools - currently hold data about your business, your staff, or your clients? Have you assessed those tools for data handling practices? Do you know what happens to your data if any of them is compromised?

 

Mathspace: The Education Sector Is Not Low-Risk

Mathspace doesn't hold financial records or medical histories. It holds student data - names, email addresses, school information, parent and guardian details. More than a million of them across Australia and New Zealand. The breach was described as one of the largest single-vendor education data exposures in APAC this year.

The lesson here isn't specific to education. It's about scale. Organisations that hold data on a large number of individuals - regardless of the sensitivity of each individual record - represent a valuable dataset when that data is aggregated. A student's name and school isn't sensitive in isolation. A million student records, with parent contact details and school affiliations, is a significant dataset for phishing campaigns, social engineering, and identity fraud.

The Mathspace breach also revealed a five-week gap between the intrusion window and public confirmation. The company identified the breach through its own internal review process rather than through an external security researcher or dark web listing. Five weeks of undetected access.

What would this look like in your business? How long would it take to detect that someone had accessed your systems? Do you have active monitoring, or would you find out the same way Mathspace did - weeks later, during an internal review?

 

The Common Thread

Three different sectors. Three different attack methods. Three different organisations. But a consistent pattern underneath all of it.

Each breach involved data that was valuable to attackers - health trial data, payroll records, student information. Each breach involved access to systems or third-party tools that were connected to sensitive information. And in each case, the breach became public at a point where the damage had already occurred.

The NCSC's Q1 2026 report recorded the first "highly significant" (C2-classified) incidents since the 2021/22 financial year - the ManageMyHealth, MediMap, and IntraCare breaches. Q2 2026 saw a 20% increase in incidents requiring specialist technical support. And now, in the first two weeks of September 2026, ZenTech, Thankyou Payroll, and Mathspace.

Adelphi Insurance Brokers' 2026 cyber market review found that 53% of New Zealand businesses reported suffering a cyber incident in 2025. That figure is not declining.

Aura Information Security general manager Patrick Sharp, quoted in RNZ's coverage this week, made the point directly: most businesses struggle with governance, especially when it comes to making an informed decision about cybersecurity. MFA is still missing in many. Some businesses aren't setting it up, or are using weak passwords. The fundamentals - not exotic zero-day exploits - are what attackers find and use.

 

What Your Business Should Do Now

This is a call to check.

The businesses most likely to be in next week's breach announcements are the ones that haven't reviewed their security posture recently, aren't sure what third-party tools have access to their data, and haven't tested whether their backups and incident response plans would actually hold up.

Here's where to start.

Audit what third-party tools have access to your business data - The Thankyou Payroll breach is a direct illustration of why this matters. Make a list of every analytics tool, reporting tool, AI tool, practice management system, and SaaS application that holds any data about your business, your staff, or your clients. Assess what data each one holds and what your options are if any of them is compromised. This is part of what our cloud drift management service addresses - the third-party application connections that accumulate over time without structured review.

Confirm your MFA is actually deployed everywhere it needs to be - Not just "we have MFA." Every account, every application, no exceptions. The ZenTech ransomware pattern, the Thankyou Payroll third-party access, the Mathspace intrusion - each could have been complicated or prevented by strong identity controls applied consistently. As we covered in our post on identity security beyond MFA, having MFA enabled in some places is different from having it consistently enforced across the whole environment.

Know where your sensitive data is - and who can access it - Health data, financial records, payroll information, client files. Before an attacker decides to target your business, the question they're answering is: what does this organisation hold, and how do I get it? Before they answer that question, you should. Our post on what Copilot can see in your Microsoft 365 environment covers the data visibility question specifically for Microsoft 365.

Test your backups - Ransomware attacks - like the one on ZenTech - depend heavily on whether the target has clean, isolated, tested backups. If you have backups but haven't tested a restoration recently, you have an assumption rather than a capability. As we covered in our post on what happens to your data if your cloud provider goes down, tested backups and defined recovery objectives are what separates a business that recovers quickly from one that doesn't recover at all.

Know who is watching your security - The Mathspace breach involved five weeks of undetected access. Zenith Technology's breach was discovered when data appeared online - not through active monitoring. For most NZ businesses without dedicated security monitoring, an attacker in their environment would be in the same position. As we covered in our post on who is watching your cybersecurity, having security tools and having someone monitoring those tools are different things.

Make sure your cyber insurance reflects your actual exposure - The breaches this week involved data sensitivity (ZenTech), third-party risk (Thankyou Payroll), and scale (Mathspace) - all factors that affect both your risk profile and your coverage terms. As we covered in our post on what a cyber insurance claim actually costs NZ businesses, the controls your policy assumes are in place need to actually be in place, or the claim fails.

 

How NSP Can Help

NSP works with NZ SMEs across every dimension of the security problem the latest breaches illustrate.

If you're not sure where your security posture stands, a cybersecurity assessment gives you a clear, prioritised picture - what's in place, what's drifted, and what to address first. It's the most direct way to move from uncertainty to a clear plan.

If you want continuous protection rather than periodic reviews, NSP's Managed Detection and Response provides 24/7 monitoring across your Microsoft 365 environment, endpoints, email, and identity - catching the suspicious activity that five weeks of undetected access would have produced much earlier.

If you want to address AI adoption and governance alongside security, NSP's Secure AI Accelerator is a programme that builds the foundations - security posture, AI governance, staff training, and documented evidence - that make AI adoption safe rather than a liability.

If you want your Microsoft 365 environment actively maintained rather than configured once and assumed to be fine, NSP's Microsoft 365 Drift Management service monitors configuration changes, permission accumulation, third-party application access, and shadow AI activity - the exact categories of risk the Thankyou Payroll and ZenTech breaches illustrate.

If you need strategic security leadership without a full-time CISO, NSP's vCISO service provides that at a business level - someone accountable for your security posture, your risk register, and your board reporting.

 

Ask Yourself

The businesses affected by the latest breaches were a clinical research lab, a payroll company, and an education platform. None of them are the kind of organisation most people picture when they think about cyber attack targets.

That's the point.

Attackers don't select targets based on sector or public profile. They select based on data value, access ease, and the likelihood of payment or leverage. New Zealand businesses across every sector hold data that meets at least one of those criteria.

The question worth sitting with isn't whether these breaches are concerning. It's whether your business would know what to do - and how quickly - if you were next.

If you're not sure, that's the conversation worth having now.

Book a free 30-minute security consultation with NSP →

Or call us directly: 0508 010 101

 

Related Reading

Let’s stay in touch!

Enter your details below to stay up-to-date with the latest IT solutions and security measures.