NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Cyber attacks against banks, MetService - experts see lockdown link, explain why your data is not at risk

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
8 Sep, 2021 05:00 PM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Image / 123rf

Image / 123rf

Why a sudden surge in cyber-attacks?

It could be yet another problem we can pin on the pandemic.

Experts see a link with New Zealand's level 4 lockdown.

Yesterday DDoS (distributed denial of service) attacks rendered Kiwibank, ANZ, NZ Post and MetService's sites inaccessible for large parts of the morning. The NZ Police website also had brownouts. For Kiwibank it was a repeat of problems experienced on Friday. ANZ has suffered fresh problems today.

"It would seem that because our situation in level 4 is as well known throughout the world, and that we are relying more on our digital services, particularly with banking, it makes sense for cyber-criminals to target those services - presumably believe that they could demand a higher ransom or that a ransom might be more forthcoming," said AUT senior lecturer in software engineering Ken Johnson.

Advertisement
Advertise with NZME.
"Our situation in level 4 is as well known throughout the world, and that we are relying more on our digital services, particularly with banking, So makes sense for cyber-criminals to target those services - presumably believe that they could demand a higher ransom," says AUT's Ken Johnson.
"Our situation in level 4 is as well known throughout the world, and that we are relying more on our digital services, particularly with banking, So makes sense for cyber-criminals to target those services - presumably believe that they could demand a higher ransom," says AUT's Ken Johnson.

Peter Bailey, GM of homegrown IT security outfit Aura (recently bought by Kordia) had a related theory.

It would be so easy to describe the DDoS "attack" in NZ relevant terms. Why can't the media just report it that way? pic.twitter.com/GwXfIWCum7

— Peter (@plambrechtsen) September 8, 2021

"We've seen a lot more DDoS and ransomware attacks over the last year than we've seen in the past. And there's speculation that it could be partly because we've been in the international press, with coverage about how well we've done with Covid. So we've come to the notice of attackers with our stronger economy - and they want to give us a bit of a go."

Bailey also has a second theory that's less flattering to NZ.

Advertisement
Advertise with NZME.

"There's also been talk over the last couple of years that as the US gets a lot stronger in cyber defence, the attackers are looking for countries that are less prepared. And, you know, New Zealand is one of those that's come up on the list that they're quite interested in," he said.

Theta head of cyber security Jermey Jones agreed that increased digitisation with Covid - while a net positive overall - made us a juicer target for hackers.

Discover more

Business

Cyber-attacks: Five ways NZ is asleep at the wheel

15 Mar 02:00 AM
Business

'Foreseeable attacks, critical gaps': Watchdog slams NZX for cybersecurity failures

27 Jan 07:16 PM
Official Cash Rate

Chris Keall: Why the Reserve Bank data breach report falls short

01 Jun 05:34 AM
Business

Budget 2021: The technology industry's verdict

20 May 05:50 AM

He added, "The price of delivering a large DDoS attack has never been cheaper or easier to deliver. Generally in these cases, it is simply extortion: 'Pay us some bitcoins or we'll turn you off'. (None of the sites affected so far had made any detailed comment on the attacks by press time. Kiwibank and ANZ would not even confirm if a cyber attack had caused their outages, let alone if any ransom had been involved or paid.)

Source /  Imperva's 2021 DDoS Threat Landscape Report
Source / Imperva's 2021 DDoS Threat Landscape Report

Whatever the reason, NZ is being disproportionately targeted for DDoS attacks, according to US security company Imperva, whose 2021 DDoS Threat Landscape Report says we are the sixth-most targeted country - albeit in the context of the US drawing easily the most fire.

Last year, cyber-attacks worldwide escalated as security holes were opened by workforces scattering to home offices, just as organised crime groups - starved of many of their usual money-making activities by lockdowns - turned to online shakedowns.

Australia reacted to that development, plus a rise in cyberattacks by state actors, by throwing billions more at cyber-security, while NZ's response, including a noticeably muted ICT spend in Budget 2021, could be measured in the order of tens of millions.

No data at risk

Some brighter news: AUT's Johnson said that while yesterday's attacks were an annoyance, and would have been a business cost for many, no data was ever at risk.

"A DDoS attack floods a website with connection requests that make any legitimate request from a customer get lost in the mix."

Advertisement
Advertise with NZME.

But while it effectively renders a website inaccessible to its regular users, there is no attempt to "break in" and steal or encrypt data.

"They block entry. There's no attempt to access the system itself," he said.

On social media, some said a DDoS attack could be a distraction, while a ransomware attack is also deployed, and a grab made for data. Johnson says that theory doesn't add up though. "A DDoS attack exhausts all of a site's resources," he said. It leaves no way to access it, and that includes baddies.

Preparing for the worst

Bailey says that while rank-and-file staff can do their bit to help stop ransomware sneaking into a network - by constantly changing passwords, and being suspicious of email attachments and so forth - stopping a flood of bots is really something that can only be done by the IT department, working with internet and security partners.

Yesterday, the Government's Computer Emergency Response Team (CERT NZ) said it was aware of a series of DDoS attacks. "We are monitoring the situation and are working with affected parties where we can," the agency said. (The GCSB's National Cyber Security Centre declined immediate comment, saying any comments in the media could tip its hand to hackers.)

"There's also been talk over the last couple of years that as the US gets a lot stronger in cyber defence, the attackers are looking for countries that are less prepared. And new Zealand is one of those that's come up on the list that they're quite interested in,"  says  Aura GM Peter Bailey.
"There's also been talk over the last couple of years that as the US gets a lot stronger in cyber defence, the attackers are looking for countries that are less prepared. And new Zealand is one of those that's come up on the list that they're quite interested in," says Aura GM Peter Bailey.

Stopping a DDoS attack is a matter of spotting the IP (internet protocol) address that floods of bot-connection requests are coming from, then blocking them (the addresses don't reveal the location of the attacker - and no one has any idea yet in the case of yesterday's attacks - but rather various PCs around the world that have been taken over by malware, then been turned into "zombies").

"The price of delivering a large DDoS attack has never been cheaper,  or easier to deliver," says head of cyber security Jeremy Jones. Photo / Supplied
"The price of delivering a large DDoS attack has never been cheaper, or easier to deliver," says head of cyber security Jeremy Jones. Photo / Supplied

But MetService got dibs from Bailey and Johnson for being able to almost immediately stand up a backup site yesterday morning - then directed its users there via social media. After it suffered DDoS attacks last year, NZX eventually implemented a similar measure so it could keep getting market announcements to investors in real-time in the event its main site suffered another DDoS attack (as with any event, NZX's trading system and data were never at risk; it was the fact that its website was forced offline, meaning it could not post simple market announcements so companies could meet continuous disclosure rules) that forced the exchange to suspend trading.

Johnson noted that while Metservice's backup site (/www2.metservice.com) lacked the bells and whistles of its regular site, and that the approach might not be suitable for every business, it was a solid prepare-for-the-worst strategy.

"If you are providing alternative access to the services that your customers demand, and your business can keep running, then ultimately, it's a good plan."

Collateral damage

"The complexity and size of these attacks means there is often collateral damage and different organisations being served by the same ISP can be affected, too," Jones said.

"One learning point here is that our design and operation of online services needs more industrial levels of DDoS protection.

"Another is that ISPs are often too slow to provide adequate protection to their customers. These attacks are large, sophisticated and fast-moving, but if your day job is delivering network services to entire populations you should know that and have the means to detect it and do something about it."

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Employment

'Like having our throats cut': Couple called into meeting, both told their jobs were gone

11 May 02:32 AM
Business

New World's $73m Pt Chevalier supermarket opening brought forward

11 May 02:01 AM
Premium
Opinion

Cecilia Robinson: 'Why didn't we learn this at school?'

11 May 12:00 AM

“Not an invisible footprint”: Why technology supply chains need optimising

sponsored
Advertisement
Advertise with NZME.

Latest from Business

'Like having our throats cut': Couple called into meeting, both told their jobs were gone

'Like having our throats cut': Couple called into meeting, both told their jobs were gone

11 May 02:32 AM

Now Didi van Heerden has been awarded $207,000 from the company and its director.

New World's $73m Pt Chevalier supermarket opening brought forward

New World's $73m Pt Chevalier supermarket opening brought forward

11 May 02:01 AM
Premium
Cecilia Robinson: 'Why didn't we learn this at school?'

Cecilia Robinson: 'Why didn't we learn this at school?'

11 May 12:00 AM
Mother of all dairy cows inducted into 'Hall of Fame'

Mother of all dairy cows inducted into 'Hall of Fame'

10 May 10:30 PM
Deposit scheme reduces risk, boosts trust – General Finance
sponsored

Deposit scheme reduces risk, boosts trust – General Finance

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP