← SecureAZ Blog

Incidents · 8 min read · Published 3 May 2026 · Reviewed 17 August 2026

What Recent NZ Cyber Breaches Teach SMEs (2024–2026 Lessons)

Latitude Financial, MediaLab, Mercury IT, and Te Whatu Ora — the recent NZ breaches that should shape your security awareness programme in 2026.

The NZ threat landscape between 2023 and 2026 has been defined by a string of high-impact breaches that affected millions of New Zealanders. Latitude Financial, MediaLab East Coast, Mercury IT (and the Ministry of Justice supply chain incident), and Te Whatu Ora data exposures all share a common pattern that should reshape how SMEs think about staff training. None of these breaches were sophisticated zero-days. Almost every one started with a credential compromise, a phishing click, or a supply chain trust failure — exactly the things awareness training is built to defend against.

This post unpacks four recent breaches and the specific lessons NZ SMEs should be drawing in 2026.

1. Latitude Financial (2023) — credential reuse and the lateral pivot

The Latitude breach exposed roughly 14 million customer records, including driver licence numbers, passport numbers, and historical financial data. The attack started with stolen employee credentials harvested from a third-party service provider. The attacker authenticated to Latitude's systems as a legitimate employee and moved laterally through environments that trusted that credential.

SME lesson: Credential reuse is your single highest-leverage attack vector. Staff who use the same password on Spotify, a courier portal, and your accounting system have created a chain that breaks at its weakest link. A compromised personal Spotify account in 2023 became a corporate breach in 2026 — the data was still in the dump. Combine phishing training with mandatory unique passwords and MFA, and the lateral pivot stops.

2. MediaLab East Coast (2022) — ransomware via service provider

MediaLab provided IT services to multiple NZ public sector clients including the Ministry of Justice. A ransomware compromise of MediaLab cascaded into data exposure for thousands of New Zealanders whose information was held by MediaLab on behalf of those agencies. The initial access was attributed to a phishing email that compromised a privileged administrator account.

SME lesson: If you provide services to other businesses or government, you are a supply chain target. Your customers' threat model includes you. The corollary: every NZ SME should treat the security of its own service providers — IT, payroll, HR — as part of its own risk register. Ask each provider what awareness training their staff complete and how often it is documented. If the answer is "we don't" or "during onboarding only", that is a finding.

3. Mercury IT / Ministry of Justice (2022) — the long tail of a single supplier

The Mercury IT incident — affecting the Ministry of Justice, Te Whatu Ora and other public sector clients — demonstrated how a single managed service provider compromise produces a years-long notification, remediation, and reputational tail. The Privacy Commissioner's reporting on the incident is still relevant reading for any NZ business that touches public sector contracts.

SME lesson: Cyber insurance and contractual requirements increasingly mandate documented staff training. NZ government tenders now routinely require proof of awareness programmes that align with NCSC minimum cyber security standards. If you intend to sell to government, supply chain due diligence will examine your training programme. "We do an annual video" is no longer a passing answer.

4. Te Whatu Ora data exposures (2024–2025) — insider risk and access control

A series of incidents involving improper access to Te Whatu Ora data highlighted that not every breach starts outside the organisation. Insider misuse — whether malicious or negligent — accounts for a growing share of NZ notifiable privacy events under the Privacy Act 2020.

SME lesson: Awareness training is not only about phishing. It is also about acceptable use, data handling, and the principle of least privilege. Staff need to know which data they are authorised to access, when accessing data outside their role becomes a notifiable event, and how to report colleagues whose behaviour creates risk. For healthcare-adjacent organisations, the HISF security awareness framework sets out these expectations explicitly.

The pattern across all four breaches

| Breach | Initial vector | Could awareness training have prevented it? |

|---|---|---|

| Latitude Financial | Credential reuse / phishing | Yes — password hygiene + phishing training |

| MediaLab | Phishing email to admin | Yes — phishing simulation + privileged user training |

| Mercury IT / MoJ | Service provider compromise | Partial — supply chain due diligence training |

| Te Whatu Ora | Insider access misuse | Yes — acceptable use + Privacy Act training |

In every case, awareness training is not the only control — but in every case, it would have meaningfully reduced the probability or impact of the breach. The cost of an effective programme is dramatically lower than the cost of a single incident: see our breakdown of the real cost of a data breach for NZ SMEs.

What an effective 2026 programme looks like

Drawing the lessons together, an awareness programme that reflects the NZ threat landscape in 2026 includes:

  • Quarterly phishing simulations — including QR-based and AI-voice scenarios, not just URL clicks
  • Annual mandatory training covering Privacy Act 2020, acceptable use, and incident reporting
  • Role-based training for privileged users, finance, and HR
  • Supply chain awareness for any staff who interact with vendors or contractors
  • Documented evidence sufficient to satisfy NCSC minimum standards, cyber insurer requirements, and Privacy Act security safeguards

SecureAZ provides this in a single platform, with NZ-localised content, NCSC NZ approved supplier status, and the documented training records that NZ insurers and government tenders increasingly require.

Start a free SecureAZ trial.

External references: