Three NZ breaches in a fortnight — and two came through somebody else’s software
On 11 September RNZ reported that security researchers were raising the alarm after three New Zealand organisations disclosed breaches in quick succession. The one closest to home for most businesses is Thankyou Payroll, a New Zealand payroll provider used by charities and small organisations. On 10 September it told customers that names, IRD numbers, email and physical addresses, bank account details and payment histories had been accessed. The detail that matters: none of Thankyou Payroll’s own systems were breached. The way in was Metabase, a third-party reporting tool it used, which had a critical flaw — CVE-2026-72898, an unauthenticated SQL injection in the password-reset endpoint, rated the maximum CVSS 10.0, confirmed by the vendor as actively exploited and on CISA’s Known Exploited Vulnerabilities list since 11 August. The company took the tool offline, forced password resets and notified the Privacy Commissioner.
The other two are different flavours of the same problem. Police are investigating a breach at health research company Zenith Technology (ZenTech), where a large number of clinical trial files may have been stolen — and as University of Auckland’s Dr Abhinav Chopra told RNZ, health data cannot be changed the way a password can, so a stolen clinical dataset stays valuable indefinitely. And Mathspace, an online maths platform used in schools on both sides of the Tasman, confirmed attackers downloaded names and email addresses of more than a million students, parents and teachers. Victoria University researcher Ben Van Der Weerd made the point about payroll firms specifically: they hold an unusual concentration of personally identifiable information, which is exactly what sells. Metabase, for what it is worth, has been hitting companies globally — Framework, Anaconda and n8n have all disclosed customer-data access through the same flaw.