NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • Deloitte Fast 50
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
    • Generate wealth weekly
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In

Advertisement
Advertise with NZME.
Home / Business

New World customers warned after ‘password spraying’ attack

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
12 Jul, 2025 02:39 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save
    Share this article
In a "password spraying" attack, a scammer uses previously compromised passwords or automated tools to try lots of common weak passwords. Image / Herald graphic

In a "password spraying" attack, a scammer uses previously compromised passwords or automated tools to try lots of common weak passwords. Image / Herald graphic

New World Clubcard members are being asked to change their online passwords after a cyber attack.

One expert is questioning why customers were allowed to set weak online passwords and have “0000″ passwords on their physical cards.

“Foodstuffs North Island and Foodstuffs South Island have identified a recent attempt by scammers to gain unauthorised access to a limited number of New World Clubcard accounts,” a spokesman for New World owner Foodstuffs said.

“This activity is consistent with what’s known as a ‘password spraying’ attack, where commonly used or previously compromised passwords are tested across many accounts.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

“We want to reassure our customers that Foodstuffs’ systems have not been breached or compromised in any way.

“The issue has arisen where some customers’ passwords have been successfully guessed by scammers using automated tools.”

The spokesman said no personal credit card data has been compromised: “Foodstuffs never stores full [credit] card numbers.”

However, a New World Clubcard account can have “New World dollars” loaded to it, earned under a rewards scheme, that can be used to buy groceries.

Advertisement
Advertise with NZME.

“As a precaution, we have temporarily disabled the ability to redeem New World dollars on affected Clubcard accounts and removed stored payment tokens linked to them,” the spokesman said.

Citing security, the spokesman would not answer questions about whether scammers had been able to order groceries, whether refunds had been paid if they had, or how many accounts were affected.

“To restore access and ensure ongoing protection, we are asking affected customers to reset their passwords, choosing a strong and unique passphrase,” the spokesman said.

Expert’s concerns

Hamish Krebs, a cybersecurity incident response expert with security firm CyberCX, who also happens to be a New World customer, got the Foodstuffs email this morning as a New World Clubcard customer. Like a number of other customers, he was told his account was not affected but that in keeping with “security best practice” he should update his account anyway.

Discover more

Business|companies

Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

15 Jun 11:27 PM
Business

$50m fine or $10K fine for data leaks? Privacy Commissioner, Goldsmith on different pages

06 Mar 04:00 PM
Technology

‘Huge upheaval’: Big Govt department's tech team to be cut

11 Jul 04:00 AM
Business

Auckland Transport warns about ‘pretend’ parking site – registered with InternetNZ using fake details

26 Mar 09:05 PM

In Krebs’ view, any transactional site should require a strong online password from the get-go.

Physical New World Club Cards also had a 0000 default PIN number - and some never changed it.

“I can confirm New World Dollars have been disabled for those customers’ cards too,” the Foodstuffs spokesman said.

Another concern for Krebs: He said he could also only find one “multi-factor authentication” (MFA) option in the New World Clubcard app – to have a code sent to a cellphone number. He said the drawback was that once logged into a Clubcard account, a scammer could change the associated cellphone number to their own.

Krebs said a scammer who accessed a Clubcard account could spend a customer’s New World reward dollars – but because a credit card could be tied to an account, they could also spend beyond the rewards balance “and buy $500 worth of beer and wine and get that delivered to any address or click and collect”.

As a New World customer, I placed an order through New World’s app, going beyond my Clubcard rewards dollar balance of $10.73 to place a $19.73 click-and-collect order with the balance charged to my stored credit card without a three-digit security code being requested.

Advertisement
Advertise with NZME.

Once logged into the New World Clubcard website, items could also be added to an order – and charged to a saved credit card – without a security code being requested.

Ability to charge but credit card details not visible

While it seems the scammers had the potential ability to charge New World purchases to the credit card associated with a compromised account, they could not see the card number, name, expiry date or three-digit security number.

“We store an encrypted token, not credit card details,” the Foodstuffs spokesman said.

“That allows the credit card to be used in transactions but ensures the card details themselves are not at risk.

“For the customers successfully targeted by the attackers, we deleted the encrypted tokens, ensuring that if the attackers attempted to use their account to order online [once the breach had been discovered], they would not be able to make a payment, thus protecting our customers.”

Change your password

“To restore access and ensure ongoing protection, we are asking affected customers to reset their passwords, choosing a strong and unique passphrase,” the Foodstuffs spokesman said.

Advertisement
Advertise with NZME.

“We are closely monitoring for any further malicious activity and working alongside external cybersecurity experts to further reinforce our defences.

“We apologise for the inconvenience. Protecting our customers’ privacy, data and trust is a top priority, and we are taking every step to respond quickly.”

Foodstuffs’ password recommendations

Foodstuff recommends customers follow the guidelines below when resetting their New World Clubcard password.

CyberCX’s Krebs said he agreed with all the guidelines, including the recommendation to “use at least 12 characters” but that as of this morning, after receiving Foodstuffs’ warning email, he still had the option in the New World Clubcard app to set a less secure six-character password.

  • Use at least 12 characters. Longer passwords are harder to crack
  • Mix character types
  • Include uppercase, lowercase, numbers, and at least one of these symbols (!@$%^&*()_+=-{};:’“,.<>?|~`)
  • Avoid common words and patterns
  • Don’t use easily guessed words like password, 123456, or qwerty
  • Don’t use personal information
  • Avoid names, birthdays or addresses
  • Use passphrases
  • Combine unrelated words into a phrase (eg BlueTiger!Drinks7Coffee)
  • Don’t reuse passwords across different accounts

Foodstuffs ‘doing the right thing’

A second cyber security expert was more positive in his take on Foodstuffs’ response.

“This is a common form of attack in which passwords have been lost in another breach, or attackers are simply trying to guess common passwords,” Aura Information Security general manager Patrick Sharp said.

Advertisement
Advertise with NZME.

“It is not a data breach, and is not caused by a weakness in New World’s systems.”

A password manager, such as LastPass or Bitwarden, is a good way to manage complex passwords on many sites effectively, Sharp said. The latest web browsers also act as password managers, suggesting strong passwords then remembering them for you (as long as you remember your master password to access your “vault” of logons).

“Foodstuffs are doing the right thing communicating proactively about this – they’ve given good detail and great advice,” Sharp said.

Chris Keall is an Auckland-based member of the Herald’s business team. He joined the Herald in 2018 and is the technology editor and a senior business writer.

Save
    Share this article

Latest from Business

New Zealand

You've got mail: NZ Post resumes business parcel deliveries to US amid new tariffs

Business

$8.6b giant Summerset makes record half-year sales

Economy
|Updated

'Lack of trust': Adrian Orr agreed to resign if RBNZ board's letter of concerns was binned


Sponsored

Why NZ businesses lag on solar and the adoption of clean on-site renewable energy

Advertisement
Advertise with NZME.

Latest from Business

You've got mail: NZ Post resumes business parcel deliveries to US amid new tariffs
New Zealand

You've got mail: NZ Post resumes business parcel deliveries to US amid new tariffs

But people are unable to send personal parcels through the service.

28 Aug 12:01 AM
$8.6b giant Summerset makes record half-year sales
Business

$8.6b giant Summerset makes record half-year sales

27 Aug 11:40 PM
'Lack of trust': Adrian Orr agreed to resign if RBNZ board's letter of concerns was binned
Economy
|Updated

'Lack of trust': Adrian Orr agreed to resign if RBNZ board's letter of concerns was binned

27 Aug 11:19 PM


Why NZ businesses lag on solar and the adoption of clean on-site renewable energy
Sponsored

Why NZ businesses lag on solar and the adoption of clean on-site renewable energy

14 Aug 09:40 PM
NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP