Major New Zealand Health Data Breach; Hackers Demand Ransom

Related

Meta AI Support Data Breach Affects Over 20,000 Instagram Accounts

What happened Meta revealed that more than 20,000 Instagram users...

Multiple US Healthcare Data Breaches Expose Millions of Patient Records

What happened Several major healthcare data breaches have been added...

Grafana Labs Refuses to Pay Ransom After Codebase Theft

What happened Grafana Labs confirmed over the weekend that an...

UK Water Company Fined After Hackers Lurked Undetected for Nearly Two Years

What happened The UK's Information Commissioner's Office fined South Staffordshire...

Share

What happened

Hackers demanded a ransom after a major New Zealand health data breach, compromising the Manage My Health portal. Identified on 30 December 2025, the attack exposed medical records of approximately 108,000–126,000 users. Threat actors operating under the name “Kazu” threatened to release over 400,000 files unless US$60,000 was paid. Compromised data included medical records, prescription information, diagnostic results, and personal contact details. Authorities and New Zealand Health Minister Simeon Brown initiated urgent reviews, while cybersecurity experts warned about identity theft and fraud risks. Exploitation leveraged unauthorized portal access, but technical specifics of the breach have not been fully disclosed.

Who is affected

Patients registered with Manage My Health, general practitioners, and healthcare organizations face direct exposure, with potential indirect impact on wider healthcare services and public trust.

Why CISOs should care

Health record breaches risk identity theft, regulatory non-compliance, and reputational damage, emphasizing the need for robust access controls and incident response in healthcare systems.

3 practical actions

Review access controls: Audit authentication and authorization policies for health data portals.

Enhance monitoring: Detect anomalous access patterns or large data exports in healthcare systems.

Prepare patient notification protocols: Establish communication strategies and support mechanisms for affected individuals.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.