NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business / Companies / Telecommunications

Businesses pay cyber-ransoms on the sly

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
29 Sep, 2024 04:00 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Many NZ companies have a policy not pay a cyber ransom but cough up anyway. Photo / Getty Images

Many NZ companies have a policy not pay a cyber ransom but cough up anyway. Photo / Getty Images

Many businesses have a policy of not paying a cyber-ransom - but pay up on the sly, according to new research.

NZ businesses are facing more cyberattacks and pressure from them with 42% of NZ businesses having experienced data breaches over the past 12 months, according to Cloudflare’s Navigating the New Security Landscape: New Zealand Cybersecurity Readiness Survey 2024.

About 42% of respondents said their organisation experienced some form of data breach over the past 12 months.

It also found that 44% of respondents who had experienced a ransomware attack within the past two years said their organisations paid a ransom, despite 89% having issued public pledges not to.

The survey covered 40 small businesses, 56 medium companies and 56 large New Zealand firms as part of a broader survey of 3844 cybersecurity decision-makers across 14 Asia-Pacific countries.

Advertisement
Advertise with NZME.

Classic weak points were identified, including untrained staff, unpatched server software and unaddressed vulnerabilities in software used to access the office from afar, and virtual private network software -which has legitimate users, but that staff could use, for instance, to beat geo-restrictions around a stream of a sports event.

On the plus side, 48% of the NZ organisations surveyed had a “zero trust” policy, versus the Asia Pacific average of 40%. The policy involves trusting no one inside or outside your organisations - in practical terms, that means incessant use of two-factor verification, by text message or authentication app when accessing services or files.

All the organisations had had a rise in ransomware over the past 12 months. But notwithstanding the number who had forked over cash to a hacker, NZ organisations are around one-third less likely to pay a ransom, according to the survey.

Advertisement
Advertise with NZME.

Emerging AI threat

Other challenges faced by respondents included a lack of cybersecurity talent (32%), and the emerging threat posed by AI (35%).

AI makes it easier for amateurs to throw a ransomware attack together. It also allows professions to use sophisticated new tactics such as real-time audio or even video-call imitations of a staff member - such as the attack that targeted the CFO at Zuru Toys.

“Prepare for AI fuelling a multiplication and intensification of attacks: AI is here to stay so CISOs [chief information security officers] need to identify ways to combat the increase in cyberthreats that this technology will engender,” Cloudflare’s report on the survey says.

“Cybersecurity leaders should be wary of simply outsourcing the problem, but there is definitely a case for examining talent models, governance frameworks, compliance or the terms of engagement with third-party vendors to see how best to keep organisations safe.”

Cloudflare is not to be confused with Cloudstrike, the security firm that created global havoc with a software upgrade that took offline millions of computers controlling retail, airline, bank and other sectors this year.)

Police: Don’t pay

Police, Cert NZ and other agencies advise against paying a cyber-ransom, on the basis it incentivises further offending, that there’s no guarantee you’ll get your data back - or that copies won’t be used to blackmail you or your customers - and that gangs use revenue from cybercrime to help fund offending in areas such as drugs and human trafficking.

Legal to pay ...

While there’s nothing black-and-white about ransomware on New Zealand’s statute books, former Auckland University Law Professor Bill Hodge told the Herald: “The Crimes Act was written in an age when a ransom was only demanded for a person, not data. But my reading is that it would not be illegal to succumb to a hacker’s demands and pay a ransom. It would be almost impossible for police to mount a prosecution.”

The previous Government, and the current one, have opposed making it illegal to pay a cyber-ransom, saying it would criminalise the victim.

Advertisement
Advertise with NZME.

The Crown has tightened up its own act, however.

“Cabinet has agreed that government agencies should not pay cyber ransoms,” the Government’s guidance reads.

“The New Zealand Government strongly discourages the payment of ransoms to cybercriminals, and urges all victims to report any cyber ransom incidents to the relevant agencies, regardless of whether a ransom is paid.”

An update to the Privacy Act 2020 made it mandatory to report any serious data breach to the Privacy Commissioner.

... unless Russia is involved

Many major ransomware gangs are based in Russia, according to analysis by security firms who have noted groups using Cyrillic script in communications, among other pointers. And Russian nationals have featured strongly in the handful of arrests related to ransomware attacks.

New Zealand’s spooks think so too. “The Government Communications Security Bureau has established clear links between the Russian Government and a campaign of malicious cyber activity targeting overseas political institutions, businesses, media and sporting organisations,” the GCSB said in a report issued before the Ukraine invasion. The Putin regime has since encouraged more malicious attacks, according to industry experts.

The war led New Zealand’s Parliament to pass the Russia Sanctions Act 2022, which means paying a cyber ransom could now constitute breaking sanctions and could result in criminal penalties of:

  1. Up to seven years in prison and/or a fine of $100,000 for individuals; and
  2. A fine of up to $1 million for organisations.

There’s a big qualifier, however. Ransomware gangs use a lot of tricks to mask the origin of any given attack, and demands are always made in bitcoin, the cryptocurrency not tied to any country. So proving a payment had been made to a party in Russia would be difficult to prove.

Chris Keall is an Auckland-based member of the Herald’s business team. He joined the Herald in 2018 and is the technology editor and a senior business writer.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Telecommunications

Telecommunications

Spark bags $47m windfall

22 Jun 09:42 PM
World

Trump gives TikTok 90 more days to find buyer, again delayed ban

19 Jun 05:53 PM
Business|companies

One NZ expands Starlink partnership to Internet of Things

15 Jun 09:34 PM

Kaibosh gets a clean-energy boost in the fight against food waste

sponsored
Advertisement
Advertise with NZME.

Latest from Telecommunications

Spark bags $47m windfall

Spark bags $47m windfall

22 Jun 09:42 PM

Funds from sale of stake in Hutchison Telecommunications will be used to reduce debt.

Trump gives TikTok 90 more days to find buyer, again delayed ban

Trump gives TikTok 90 more days to find buyer, again delayed ban

19 Jun 05:53 PM
One NZ expands Starlink partnership to Internet of Things

One NZ expands Starlink partnership to Internet of Things

15 Jun 09:34 PM
Premium
Stock Takes: Why NZ's largest firms are suddenly ripe for takeover talks

Stock Takes: Why NZ's largest firms are suddenly ripe for takeover talks

12 Jun 09:00 PM
Engage and explore one of the most remote places on Earth in comfort and style
sponsored

Engage and explore one of the most remote places on Earth in comfort and style

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP