NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Ransomware: How Toll got hit for a second time within months

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
6 May, 2020 05:43 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Photo / file

Photo / file

Toll Group says a fresh ransomware attack is "unrelated" to one that took many of its systems offline between late January and early March this year.

The company faces the fresh attack at a time when it has asked staff to work four-day weeks as a Covid-19 cost-saving measure. And when a new chief information officer, King Lee, is just getting his feet under his desk (Lee's predecessor, Francoise Russo, left at the end of March; Toll says her departure was unrelated to the New Year security breach).

READ MORE:
• Kiwis lose $1m to sim card scam

Still, security experts say Toll's experience with the earlier attack should help it recover its systems this time.

And while the second breach of the company's systems within weeks is an embarrassment to the company's technology partners, who include NZ's Datacom, Toll chairman John Mullen has also dropped a heavy hint that the first attack was the result of human rather than technical frailty.

Advertisement
Advertise with NZME.

Mullen, who is also the chairman of Telstra, told the AFR on March 10, "I've certainly learned a terrible lesson from this last month or two, you think you're pretty robust and have been audited and have the certificates and all these things so you can tick the box, [but] you are vulnerable."

The chairman said around 50 per cent of Toll's systems were in the cloud "and they were the worst hit."

But he also heavily implied that the Russian hackers suspected of being behind the attack got to Toll through one of its employees.

Advertisement
Advertise with NZME.

"It is an element of human behaviour that creates these entry points or the chink in the armour, it is rarely the actual firewall that didn't work," Mullen said.

"People somehow get access to a master password, whether it's via guile or whether it's through criminal activity or bribing. They will use human weaknesses to get around the system."

Discover more

Business

Air NZ service provider Travelex held to ransom by hackers demanding $8.5m

07 Jan 11:34 PM
Business

Juha Saarinen: Don't keep quiet about ransomware attacks

04 Feb 04:00 PM
Business

Transport giant - finally - admits to ransomware attack

05 Feb 04:43 AM
Business

Kiwis lose $1m to sim card scam

02 May 09:26 PM

'Doxing' is new go-to-tactic

Asked if "human weakness" had been formally identified as the factor behind the first attack, and if so what action was taken, a Toll spokesman said, "We are not able to provide any information on this given the inherent sensitivities involved in making details public to perpetrators of such attacks."

However, a report released overnight by security company Eset picked up on the human frailty scheme. It says that during the first quarter, ransomware attackers "added doxing as their new go-to tactic.

Doxing is the practice of blackmailing someone by threatening to make compromising information about them available on the internet.

Why weren't defences tightened?

Regardless of whether a rogue staffer or a technical vulnerability did Toll manage to get hit again, just weeks after Russian ransomware attackers demanded a "hefty" amount of money to unlock its systems?

Last night, the spokesman would only say, "We don't have anything on that at this stage, except to point out that the ransomware variant is different to the last one and that the two incidents are unrelated."

The January attack saw what was thought to be a Russian group hijack Toll's systems using "Mailto" ransomware, also known as "Kokoklock."

Advertisement
Advertise with NZME.

"Working with IT security experts, we have identified the variant to be a relatively new form of ransomware known as Nefilim," a Toll spokesman said.

Deja vu all over again

As with the earlier attack, Toll staff have had to resort to using their own computers, Gmail addresses and manual processes to keep the transport and logistics giant running over the past 24 hours.

Late yesterday, the Japan Post-owned, Melbourne-based company, which has operations in 50 countries - including New Zealand, where it has 600 vehicles - confirmed it had been hit by a second ransomware attack.

Image / 123rf
Image / 123rf

It was working with customers to minimise disruption, it said, but it expected manual workarounds to be in place for at least the remainder of the week.

"In New Zealand, while our Global Express operations were affected initially by the incident, the team, with the support of Toll's New Zealand-based technology partners, has been able to reactivate the customer portal and customer support lines, thereby limiting any impact on customers," a spokesperson said.

"Toll has no intention of engaging with any ransom demands, and there is no evidence at this stage to suggest that any data has been extracted from our network."

The company would not immediately name its NZ-based technology partners, but Datacom features its work for Toll in a 2020 case study.

Datacom, which had no immediate comment, can at least take succour from the fact that Toll's NZ systems appear to have had suffered limited impact from the latest attack.

Hospitals spared during pandemic

There have been a number of high-profile ransomware attacks recently, including the January attempt to extort $8.5m from UK-based Air New Zealand foreign exchange partner Travelex (which, like Toll, chose to grind out a multi-week rebuild of its systems rather than pay up; no Air NZ service was affected).

Eset says at least US$140 million has been paid to ransomware attackers over the past six years, according to a February 2020 FBI presentation that tracked bitcoin movements associated with attacks.

Eset's Q1 report notes one positive, however: A number of ransomware "families" have released public statements promising not to target health or medical organisations so as not to worsen the effects of the pandemic.

What to do if you're hit by ransomware

New Zealand businesses or individuals hit by a cyber-attack are advised to contact Crown agency CERT (the Computer Emergency Response Team) as their first step.

CERT acts as a triage unit, pointing people to the right law enforcement agency or technical contacts.

CERT director Rob Pope and police both advise against paying up on a ransomware demand, even if the sum involved is modest.

They say there is no guarantee that data will be returned, or unlocked. They also caution that while paying a small ransom can be convenient, the money can help fund Eastern European gangs who are also involved in the likes of drug and human trafficking.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Airlines

Pilot group to honour Erebus legacy with safety award

17 Jun 07:00 AM
Premium
Business

The NZ boardrooms where women buck gender pay gap trend

17 Jun 06:00 AM
Premium
Shares

Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

17 Jun 05:48 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Pilot group to honour Erebus legacy with safety award

Pilot group to honour Erebus legacy with safety award

17 Jun 07:00 AM

The industry faces challenges but hopes to bring newcomers and veterans together.

Premium
The NZ boardrooms where women buck gender pay gap trend

The NZ boardrooms where women buck gender pay gap trend

17 Jun 06:00 AM
Premium
Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

17 Jun 05:48 AM
Median house prices down again, sales taking longer: monthly report

Median house prices down again, sales taking longer: monthly report

17 Jun 05:32 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP