NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business / Markets

NZX halts trading; website down for a third day in a row

NZ Herald
27 Aug, 2020 03:10 AM8 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Photo / File

Photo / File

The New Zealand Stock Exchange website crashed for a third day in a row, just as the S&P NZX-50 was 8 points short of its all time high.

Experts say apparent cyber attacks causing the platform failure as a very serious attack on critical infrastructure in New Zealand. And the fact that it's happened on a third day indicates a high level of sophistication and determination.

In a statement this morning NZX said it had to halt trading at 11.10am on its cash markets, due to a systems connectivity issue.

"NZX is continuing to work with its network provider [Spark] to investigate the source of the issue, following volumetric DDoS (distributed denial of service) attacks from offshore on 25 and 26 August."

The Exchange was hit by a cyber attack on Tuesday afternoon, halting trading for an hour.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Hamilton Hindin Greene chief financial officer Grant Williamson said the NZX outages were very frustrating for all involved.

"It is really creating a build up in orders that can't be actioned until the market opens again."

Williamson said he hadn't seen anything like this in a long time and noted it was probably the 1990s when he last saw it.

Advertisement
Advertise with NZME.

"It is extremely frustrating." Williamson said in the majority of cases it hadn't affected its clients but it could cause problems if something happened offshore and share prices moved strongly upwards or downwards and left a big gap when the NZX started trading again. He said it was waiting to hear from the NZX on when the issue would be fixed.

"I'm sure they are working extremely hard. I just hope this will be the last one we see."

READ MORE:
• NZX down again: Expert sees profit-driven extortion attempt

And the NZX went down again yesterday at 11.24am and came back online around 12.20pm - only to go offline again around 1.20pm before full service was restored at 3pm.

Discover more

Agribusiness

NZ King Salmon's plan to ride out stormy Covid waters

27 Aug 06:00 AM

Shane Solly, senior portfolio manager at Harbour Asset Management, said he expected the exchange and the broking community will pick up the activity pretty quickly once service is resumed.

"Certainly disruptive... other than not helping with price setting on a busy day for company results its not causing liquidity problems for institutional investors at this stage."

Extortion warning

Declan Ingram, deputy director of Crown cybersecurity agency Cert NZ, said his organisation never commented on individual cases, because it did not want to inhibit organisations from reporting problems.

But late last year, Cert did issue an alert around DDoS extortion attempts by Russian gangs - or at least gangs claiming to be Russian - who were targeting the financial sector in New Zealand.

"In 2019 we received 84 incident reports about DDoS attacks. In particular, cyber attackers emailed organisations alerting them that they would be subject to a DDoS attack unless they paid a ransom before a specified deadline. In some instances, the attackers initiated a warning or demonstrative attack against the organisation's IP network to prove their intent.

"Cert NZ does not recommend paying ransoms, as this could result in being targeted again," Ingram said.

Advertisement
Advertise with NZME.

That might be the official advice, but Wellington lawyer Michael Wigley has said there are some situations when paying up is the pragmatic choice - and Garmin reportedly paid a recent $14m ransom demand.

'Profit-driven' attacks

NortonLifeLock senior director Mark Gorrie told the Herald he saw financial motivation behind the twin attacks on the NZX.

"A distributed denial-of-service attack is one of the most powerful weapons on the internet, it overwhelms a site or service with more traffic than the server or network can accommodate. DDoS attacks are a weapon of choice by profit-motivated cybercriminals," Gorrie said.

"In the case of the NZX, we would guess the motivation behind the attack is profit-driven."

Cybercriminals traditionally send ransom demands before a DDoS attack, Gorrie said.

"It's financially driven in that regard, they also seek to breach systems and find high-value information, such as bank details or other personally identifiable information. This too can be ransomed, or sold on the dark web for financial gain. Don't underestimate cybercriminals. They're highly capable and well-resourced to sustain an attack such as the one happening to the NZX."

Advertisement
Advertise with NZME.

Gorrie added, "It's worth noting that in 2015 and 2016, a criminal group called the Armada Collective repeatedly extorted banks, web host providers, and others. We don't know why the attack happened, but cybercriminal motivation is more often than not about the same thing: Money."

NZX has so far refused to comment on Cert NZ's extortion alert or Gorrie's theory that the attacks are financially-motivated.

Security expert Ayers was surprised by the turn of events, tweeting: "Doesn't the NZX have DDoS protection?"

Spark had no further comment last night but is expected to give more information this morning.

Many motivations

Some DDoS attacks are executed for kicks, to prove a hacker's chops; some are politically motivated; others have criminal intent.

They have been out of the headlines for a couple of years, as hackers have turned more toward ransomware attacks that see data encrypted then a sum demanded for its release.

Advertisement
Advertise with NZME.

The Russian DDoS attack covered by the Cert NZ warning is variously known as "Fancy Bear" or "Cozy Bear".

The GCSB says it has prevented $100 million in harm from cyberattacks since 2016, and its cyberattack defences extend to un-named private sector players - but a spokesman said this morning it treats incidents as commercial in confidence to encourage organisations to disclose attacks.

'Serious attack on NZ infrastucture'

AUT computer science professor Dave Parry said, "This is a very serious attack on critical infrastructure in New Zealand. The fact that this has happened on a second day indicates a level of sophistication and determination which is relatively rare.

"DDoS attackers normally infect large numbers of 'innocent' computers with malware, turning them into 'bots' that can be instructed to keep trying to access the affected site. It's like large numbers of people all shouting at you at once – you can't distinguish the real messages from the false ones.

Normally there are two main ways to react, Parry said:

• Shut down the 'bots' – often by getting users to update security patches and delete the malware.

Advertisement
Advertise with NZME.

• Block the IP addresses of the 'bot' machines using a firewall - blacklisting - so that the NZX site doesn't have to deal with them.

"Because this is coming from overseas, the first option is difficult although there will be communication with legitimate ISPs and governments overseas. For the second option, Spark will be looking at network traffic to identify sources and block them. Sophisticated attackers will be changing the IP addresses of the attacking computers, potentially via Virtual Private Network (software, turning them on and off and also adding new ones).

"The GCSB will be involved along with Cert in trying to identify the source of the attack. Unfortunately, the skills and software to do this are widely available and the disruption of Covid and people working from home all over the world potentially with lower security on their computers means that these attacks are easier than usual."

Communications Minister Kris Faafoi said the NZX attack did not bear the hallmarks of a state actor, according to advice he had received today.

But Parry responded that state-backed hackers often mimicked the behaviour of private hackers.

Parry added, "These sort of attacks can be mounted by governments or private criminal gangs. Recently, Australia has pointed the finger at the Chinese government for similar attacks; the Chinese government has strongly denied this. As yet, there is no evidence that this attack is by an overseas government. Criminal gangs, especially if they are based in poorly-regulated countries, can use these attacks to demand ransoms.

Advertisement
Advertise with NZME.

"This is not an issue around New Zealand computers being vulnerable to security breaches, but it is worth checking that anti-virus and security patches are up to date, and that people running websites, etc. notify their ISP if there is unusual activity."

What is a DDoS attack?

Security company NortonLifeLocks says criminals prepare for a DDoS attack by taking over thousands of computers. These are often referred to as "zombie computers". They form what is known as a "botnet" or network of bots. These are used to flood targeted websites, servers and networks with more data than they can accommodate.

A volume-based or "volumetric" DDoS attack, which was apparently the variant that hit the NZX, sees massive amounts of traffic sent to overwhelm a network's bandwidth, NortonLifeLock says.

The company says a DDoS attack has to be repelled at the internet service provider level (often this involves temporarily blocking traffic from certain IP addresses).

But it is also a good idea to keep your security software up to date so your PC does not unwittingly become part of a botnet attack.

The NZX did not immediately respond to questions about whether it had received any extortion demand, whether its communications setup involved multiple providers for redundancy, and what steps were being taken to avoid another attack.

Advertisement
Advertise with NZME.
Save

    Share this article

Latest from Markets

Premium
Shares

Market close: NZ sharemarket rises as gentailers make gains

09 May 06:03 AM
Premium
Business|markets

Allbirds predicts turnaround - finally - if lucky break on tariffs holds true

09 May 12:23 AM
Premium
Stock takes

Stock Takes: Will reporting season see the end of a bear market?

08 May 09:00 PM

One tiny baby’s fight to survive

sponsored
Advertisement
Advertise with NZME.

Latest from Markets

Premium
Market close: NZ sharemarket rises as gentailers make gains

Market close: NZ sharemarket rises as gentailers make gains

09 May 06:03 AM

The NZ sharemarket rose strongly today as gentailers made gains across the board.

Premium
Allbirds predicts turnaround - finally - if lucky break on tariffs holds true

Allbirds predicts turnaround - finally - if lucky break on tariffs holds true

09 May 12:23 AM
Premium
Stock Takes: Will reporting season see the end of a bear market?

Stock Takes: Will reporting season see the end of a bear market?

08 May 09:00 PM
Premium
Pushpay insider trader loses latest bid for suppression

Pushpay insider trader loses latest bid for suppression

08 May 06:16 AM
Connected workers are safer workers 
sponsored

Connected workers are safer workers 

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP