NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business / Economy / Official Cash Rate

Data breach: RBNZ insider warned about underinvestment in security

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
12 Jan, 2021 02:00 AM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

The RBNZ was warned about the risk of underinvestment. Photo / Getty Images

The RBNZ was warned about the risk of underinvestment. Photo / Getty Images

The Reserve Bank has revealed that it was an overseas provider whose systems were breached, potentially exposing sensitive RBNZ files. That's drawn the ire of a local IT industry group that says the incident highlights a wider failing in government strategy that has weakened our defences.

The data breach also followed a May 2020 consultation document by the bank's chief information officer, Scott Fisher, that highlighted the need for more investment in IT, and a sweeping restructure of its IT structure and personnel.

Fisher's report said there was "high operational risk due to technical obsolescence and an underinvestment in security across many of the core technology platforms".

It added: "Our people lack the modern digital tools, data and systems required to effectively collaborate and to support informed decision-making."

Advertisement
Advertise with NZME.

The Herald has asked the RBNZ how many of Fisher's recommended changes were implemented. A second RBNZ initiative, involving enhanced cyber-security for its partners, is still subject to a consultation process that closes on January 29.

On Sunday, the RBNZ said it was responding with urgency after a third-party service, now named as US-based Accellion, was illegally accessed.

The RBNZ uses Accellion to share data with banks and insurance companies.

Reserve Bank of NZ Governor Adrian Orr says the attack did not directly target his institution. Photo / Mark Mitchell
Reserve Bank of NZ Governor Adrian Orr says the attack did not directly target his institution. Photo / Mark Mitchell

Overnight, Reserve Bank governor Adrian Orr said the Accellion file-transfer system had been taken offline while investigations were under way.

Advertisement
Advertise with NZME.

"This wasn't a specific attack on the Reserve Bank, and other users of the file-sharing application were also compromised.

"Our core functions and New Zealand's financial system remain sound, and Te Pūtea Matua is open for business. This includes our markets operations and management of the cash and payments systems."

Discover more

Business

Cyber defences: How Australia's $1.4b boost compares with NZ

30 Jun 05:00 PM
Business

US, NZ attempts to fend-off massive cyberattack at risk - because of weird Trump fixation

19 Dec 08:00 PM
Business

Ben Kepes: The old cybersecurity lesson from the Reserve Bank breach

11 Jan 05:00 AM
Business

$700m data centre for Southland: Proposal could hinge on an age-old question

15 Dec 04:42 AM

Work is continuing to confirm the nature and extent of information that has been potentially accessed. The compromised data may include some commercially and personally sensitive information, Orr said.

CHRISTMAS DAZE?

Meanwhile, the National Cyber Security Centre, a unit of the GCSB, has confirmed it is assisting the Reserve Bank following the hack.

A cyber-security insider told the Herald that Accellion first notified all of its customers, including the RBNZ, of the file-sharing breach on December 24 and issued a patch, but that the RBNZ did not implement the patch or take its files offline until January 7.

Neither the RBNZ nor Accellion (which did not immediately respond to questions) has given a timeline for the data breach.

The insider said around 30 Accellion customers had been hit by the breach, which involved an SQL-injection attack, where malicious code is planted that allows a hacker to view, modify or delete files on a database.

Advertisement
Advertise with NZME.

The Accellion product involved, FTA (File Transfer Appliance) is some 20 years old. The company has been urging clients to upgrade to a newer service Kiteworks, a spokesman said.

NZRISE: WIDER QUESTIONS RAISED

Meanwhile, NZRise cofounder Don Christie says the incident raises broader questions about not just the Reserve Bank's IT policy, but the Government's wider technology strategy.

While acknowledging that the central bank takes security very seriously, Christie questions its approach to file-sharing.

"It seems likely that RBNZ is using a third-party platform and it seems likely that this would be a very high-value target for hackers, similar to SolarWind which was hacked last year and used widely by government agencies across the world," he says.

"In my view, the NZ Government needs to urgently review its IT strategy," adds Christie, who is also a director of one of the largest local IT services and cloud providers, Catalyst.

"Right now, individual agencies are being mandated to move as fast as possible to overseas infrastructure and overseas SaaS [software-as-a-service] suppliers. That's very short-term thinking and requires a high degree of effectively unproven trust. Time and time again the model has been proven to fail as state-sponsored warfare becomes more prevalent."

NZRise cofounder Don Christie says Crown agencies are offshoring rather than building national resilience and capability. Photo / File
NZRise cofounder Don Christie says Crown agencies are offshoring rather than building national resilience and capability. Photo / File

An over-reliance on this one-size-fits-all strategy leaves NZ without the agility to respond to threats and compromises at a local level, Christie says.

"It also leaves us vulnerable to the whims of overseas actors. Who knows who would have control over many of these platforms had the coup attempt of January 6 in Washington DC been successful?"

An NZRise study released in November found that only about a third of government IT tenders, by dollar value, were awarded to New Zealand-owned companies for the previous year.

The lobby group argues that more business should be awarded locally, in part for skills development and to increase our tax base, and in part because of issues such as data sovereignty, and the fact that multinationals often prove difficult to regulate.

"We are simply not building a national view on resilience and capability and we are not co-ordinating investment and procurement across government agencies. If we put more focus on the latter the investment case for building much more shared infrastructure and capability in New Zealand would become far more positive," Christie says (a theme he addresses in the video below from the 11-minute mark).

"This is not to say that New Zealand tech is more secure than anyone else's but we can verify and audit respond much more easily onshore than we can offshore. Indeed, many NZ companies experience far more oversight than our overseas competitors simply because we are so close," Christie says.

"Keep in mind that the Europeans are about to spend billions of Euros building their own cloud and other infrastructure. It's likely this investment will produce more open source systems, such as Open Stack and Kubernetes that NZ can leverage. Indeed, if we played our cards right we could think about joining that initiative with a view of giving NZ more technical independence.

"This rethink will require good political leadership and a radical shake-up of Government IT leadership."

CYBERATTACKS SURGE, NZ SPENDING STUTTERS

The past 12-months have seen an escalation in cyberattacks, according to Crown agency Cert (Computer Emergency Response Team) NZ, with attacks increasing by 33 per cent year-on-year.

August and September saw the GCSB come to NZX's aid as the local stock exchange struggled to repel a series of DDoS (distributed denial of service) attacks that overwhelmed its website.

Earlier in 2020, there were cyberattacks on multiple corporate targets including Fisher & Paykel Appliances, Toll Group and Lion.

In F&P Appliances' case, a "ransomware" gang leaked a number of its spreadsheet and planning files on to the internet in a bid to pressure the company to pay for the return of its stolen files. F&P refused.

AUT computer science professor Dave Parry told the Herald that a Covid was a double-whammy had contributed to the dramatic rise in cyberattacks.

The pandemic has spurred a working-from-home boom, often involving much lower security, at the same time that lockdowns around the globe had reduced many of organised crimes' usual "real-life" avenues - leading to a spike in cybercrime.

Businesses were being targeted to exploit the gaps in security that were opening up as staff shuffled files between work and home - and simply because commercial organisations are richer targets.

Across the Tasman, Scott Morrison's government increased cyber-defence spending by A$1.35 billion last year, while NZ's increase of its already smaller per-capita budget was in the single-digit millions, with the issue gaining no traction at the election.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Official Cash Rate

Premium
Business|economy

Jobless rate better than expected, part-time worker increase credited

07 May 03:30 AM
Premium
Economy|official cash rate

Inside Economics: How much Government debt is too much?

07 May 12:30 AM
Economy|official cash rate

'Significant risk': Tariffs heighten volatility, Reserve Bank warns

06 May 10:48 PM

One tiny baby’s fight to survive

sponsored
Advertisement
Advertise with NZME.

Latest from Official Cash Rate

Premium
Jobless rate better than expected, part-time worker increase credited

Jobless rate better than expected, part-time worker increase credited

07 May 03:30 AM

The labour market remained weak and disinflationary, economists say.

Premium
Inside Economics: How much Government debt is too much?

Inside Economics: How much Government debt is too much?

07 May 12:30 AM
'Significant risk': Tariffs heighten volatility, Reserve Bank warns

'Significant risk': Tariffs heighten volatility, Reserve Bank warns

06 May 10:48 PM
Premium
Adrian Orr surfaces for farewell party with Reserve Bank staff

Adrian Orr surfaces for farewell party with Reserve Bank staff

02 May 06:04 AM
Connected workers are safer workers 
sponsored

Connected workers are safer workers 

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP