NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • Deloitte Fast 50
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In

Advertisement
Advertise with NZME.
Premium
Home / Business

Dark web password risk: NZ Govt, healthcare provider, bank staff logins found for sale – security expert

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
5 Aug, 2025 03:15 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save
    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

New Zealand logins and passwords have been found for sale on the dark web. Image / Herald Network graphic

New Zealand logins and passwords have been found for sale on the dark web. Image / Herald Network graphic

A cyber security start-up says it has found active logons – including passwords – for sale on the dark web for staff at New Zealand Government agencies, local healthcare providers and one of the big four banks.

The firm, nWebbed, says its “NZ Cybersecurity Study” analysed 30 billion credentials for sale on the dark web, found more than 198,000 compromised credentials linked to New Zealand organisations and companies.

According to its founder, Julian Wendt, these include:

  • 18,000+ NZ Government worker logins
  • 3200 banking staff accounts
  • 2000 healthcare workers with privileged access

Some of the healthcare logins had been used as recently as last month, Wendt said. A major bank logon had been used in May.

Advertisement
Advertise with NZME.

Wendt would not name those affected for security reasons, but said he had shared his findings with the healthcare providers and others affected by apparent active account breaches.

He had also informed the Office of the Privacy Commissioner (OPC) and the GCSB’s National Cyber Security Centre (NCSC) about his investigation, he said. A spokeswoman for the OPC said, “To date, OPC have not had any discussions on this issue.” NCSC had no immediate comment.

Hackers gaining access to a healthcare staffer’s login didn’t necessarily mean security holes in a hospital’s network or a successful “phishing” attack (when a hacker pretends to be a legitimate service).

It could be that the staff member used their work email address – and their work password – when they created an account with another site, which was then compromised.

Advertisement
Advertise with NZME.
 Founder of nWebbed, Julian Wendt.
Founder of nWebbed, Julian Wendt.

The Herald sighted a list of logins and passwords (the latter obscured by Wendt) used by employees of a private company (not in banking or healthcare).

Some of the logins were 10 or more years old, and all had been used to set up accounts with third-party sites rather than being active logins for their company’s own systems.

Discover more

Business

$50m fine or $10K fine for data leaks? Privacy Commissioner, Goldsmith on different pages

06 Mar 04:00 PM
Airlines

Qantas cyber attack hackers net 10,000 meal preferences, 1.3 million addresses

09 Jul 04:50 AM
Technology

‘Huge upheaval’: Big Govt department's tech team to be cut

11 Jul 04:00 AM
Business|companies

Government's giant internet, security upgrade under way for 2500 schools

17 Jul 02:00 AM

The company concerned forced its users to constantly change its passwords, with logins also subject to multi-factor authentication in the form of confirmation messages sent to a user’s cellphone.

However, Wendt said he has seen credentials for sale on the dark web within minutes of an attack and that multi-factor authentication could be circumvented if a hacker had even brief access to a network.

“Most organisations are watching the perimeter, not what’s already leaked,” he said.

Credentials and documents from previous breaches were often sitting on the dark web without an organisation realising.

What does it cost to buy stolen credentials?

Wendt says he’s found some Kiwis’ credentials sloshing around on the dark web for free.

He says hackers often display a limited number of users’ credentials (including logon names and full passwords) as a free taster for a full stolen list. At other times, they simply display them to brag.

Advertisement
Advertise with NZME.

And when a username and password is tied to, for example, a specific bank account with a known balance, it can attract a premium price (see list below).

However, most of the 198,000 compromised credentials that Wendt found came within bulk lots, available at low cost.

He showed the Herald one post where a seller was providing free access to 900,000 credentials as a taster for a collection of 200 million – available for a one-off cost of US$2000 ($3390) or a via a monthly subscription to the seller’s “collection” for US$200 for your first month then US$100 per month.

A June 2025 study by multinational credit reporting company Experian found the following prices for individual credentials on the dark web (its US dollar finds are converted to rounded NZ dollars):

  • Hacked Gmail account: $8
  • Hacked social media account: $33 to $42
  • Passport: $83
  • Driver’s licence: $250
  • Crypto account details: $33 to $4410

A separate study by managed network and security provider Crowdstrike said typical dark web prices also included:

  • Stolen bank login, minimum $2000 in account: $60
  • Stolen credit card details, balance up to $5000: $125

What is the dark web?

Wendt borrowed a Star Wars phrase to describe the dark web as a “wretched hive of scum and villainy”.

More specifically, he said it is “an area of the internet that requires special software to access”.

“It’s not indexed by search engines by Google; you have to know where you want to go before you start – some ‘surface’ websites help with that.”

Once you make it to one dark web site, it often grants access to others.

Wendt says his earlier career has included working for Hackers Without Borders, a volunteer group that has helped the Red Cross and other non-profits close vulnerabilities in their tech systems.

He says he set up the (now six-person) nWebbed in mid-2023 out of “frustration” that there was no middle ground between basic free services for tracking if your credentials were on the dark web, such has as the New York Times-namechecked HaveIBeenPwned, and corporate services that cost hundreds of thousands of dollars.

Wendt says his firm has used AI and machine learning in its analysis and stalking of dark web cyber-crime platforms.

He adds, “I’ve been in this game for well over a decade, so have access to some of the channels where cybercriminals often share their loot quite freely.”

Use a pass phrase, not a password

This far into the cyber-security crisis, most people are aware of the usual tips, which include:

  • Using a different password for every service
  • Using a complex password including names and special characters
  • Using multifactor authentication (MFA – a confirmation message sent to a cellphone number or app) when it’s an option
  • Never accessing online banking or any other sensitive service over a public Wi-Fi network.
  • Using a password manager – which could be the password manager built into your web browser – to suggest (and remember) a strong password for every site
  • Run constant health checks (for example, in the most popular web browser, Chrome, click the three dots at top right, Passwords, then Password Manager then click the options to see weak passwords and repeated passwords)

Wendt says his number one security tip is to use a “pass phrase” as your password for a site.

“It could be a line you’ll be able to remember because it’s from one of your favourite songs, books, or movies,” he says.

A number of security experts have recommended using a pass phrase in security tips they’ve supplied to the Herald.

For Wendt, it’s his absolute number one tip for defeating hackers’ automated systems.

“It’s length that makes the difference, more than complexity,” he says.

In his view, forcing staff or customers to constantly change passwords can have its drawbacks. Some would get fed up and use a guessable password and only make a minor tweak each time, such as changing a number on the end.

Chris Keall is an Auckland-based member of the Herald’s business team. He joined the Herald in 2018 and is the technology editor and a senior business writer.

Save
    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Shares

Market close: Strong lead from US carries NZX 50 up 1.5%

Construction

Downer appoints new NZ managing director to drive growth

Premium
Business

Brewing industry shake-up: Watchdog says four key issues in Kegstar-Konvoy merger


Sponsored

AI Month: How 2degrees will put AI tools in the hands of every employee

Advertisement
Advertise with NZME.

Latest from Business

Premium
Premium
Market close: Strong lead from US carries NZX 50 up 1.5%
Shares

Market close: Strong lead from US carries NZX 50 up 1.5%

'Bad news is good news,' one analyst said.

05 Aug 06:19 AM
Downer appoints new NZ managing director to drive growth
Construction

Downer appoints new NZ managing director to drive growth

05 Aug 05:30 AM
Premium
Premium
Brewing industry shake-up: Watchdog says four key issues in Kegstar-Konvoy merger
Business

Brewing industry shake-up: Watchdog says four key issues in Kegstar-Konvoy merger

05 Aug 05:00 AM


AI Month: How 2degrees will put AI tools in the hands of every employee
Sponsored

AI Month: How 2degrees will put AI tools in the hands of every employee

28 Jul 10:11 PM
NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP