TechNewsReel
Live

NZ health and education sectors hit by cluster of data breaches

Rapid-fire attacks targeting clinical and personal data highlight the growing vulnerability of SMEs holding high-value information.

TechNewsReel Newsroom · September 11, 2026

New Zealand has suffered a series of significant data breaches targeting the education, health research, and payroll sectors. The rapid succession of these attacks has prompted cybersecurity experts to warn that the risk profile for companies holding sensitive data has shifted upward.

Among the most widespread incidents, the online learning platform Mathspace reported a breach impacting more than one million users across New Zealand and Australia. The incident potentially exposed the names and email addresses of both students and teachers. In Dunedin, health tech firm Zenith Technology (ZenTech) confirmed that a large number of files related to clinical trials were stolen, an event that has triggered a police investigation. Additionally, payroll provider Thankyou Payroll was compromised via a global security vulnerability found in Metabase, an open-source analytics tool.

The shift in risk

These breaches occurred in quick succession, specifically targeting organizations that manage high-value personally identifiable information (PII), financial records, or sensitive biological data. Industry experts note that many companies previously underestimated the likelihood of such attacks. Recent incidents have demonstrated that New Zealand firms are increasingly viewed as viable targets by cybercriminals.

Why sensitive data is targeted

The nature of the stolen information makes these breaches particularly damaging. Unlike passwords, which can be reset, biological and financial identifiers are static. Dr Abhinav Chopra, a cybersecurity expert at the University of Auckland, noted that clinical information—including data on allergies and bodily functions—is information that "cannot be changed."

This permanence makes such data highly lucrative on the dark web. Ben Van Der Weerd, a cybersecurity researcher at Victoria University, explained that payroll companies are prime targets because they hold vast amounts of PII. "This data goes for a lot of money on the dark web," Van Der Weerd said, highlighting how such information is used for sophisticated phishing and ransom attempts.

The vulnerability of SMEs

These incidents underscore a critical vulnerability among small-to-medium enterprises (SMEs) that handle sensitive data. While these firms may lack the robust security infrastructure of larger corporations, they often hold the same high-value assets that attract attackers. The use of third-party tools, such as the Metabase vulnerability that affected Thankyou Payroll, further illustrates how a single global flaw can create a cascading effect across multiple organizations.

As investigations into the ZenTech and Mathspace breaches continue, the focus remains on whether these attacks were coordinated or the result of opportunistic exploitation of known vulnerabilities. For now, the cluster serves as a stark reminder that static personal data remains a permanent liability once compromised.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.