NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Who was behind the NZX attacks? A broad outline emerges

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
10 Sep, 2020 05:36 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Hackers are so good at covering their traces it's hard to tell a criminal from a state actor. Image / NZ Herald graphic

Hackers are so good at covering their traces it's hard to tell a criminal from a state actor. Image / NZ Herald graphic

Now that the dust has settled, are we any more clear who was behind the five-day series of cyberattacks on the NZX?

In short, no - though the expert consensus is firming around a profit-motivated criminal enterprise over a state actor, kids trying to prove their chops, or hackers driven by malice (one ex-Spark manager noted that the attacks on the NZX - a marquee Spark customer - coincided with Brenton Tarrant's sentencing. He floated the idea they could be a revenge attack for the telco, and its peers, blocking 4Chan and other fringe online sites in the wake of the Christchurch mosque shootings after they shared banned content).

"Given the actions of the actors to date, and what we have learned from our international partners, it is more likely that this is the work of sophisticated and well-resourced cyber-criminals," a GCSB spokesman told the Herald this afternoon.

"Work to identify the actors is ongoing," the spokesman said. He would not comment on any operational details.

Advertisement
Advertise with NZME.

The spy agency assisted the GCSB with its response.

AUT computer science professor Dave Parry takes a similar tack.

"I think it is most likely to be a criminal gang that would have preferred to get a ransom but, when they didn't, continued to show their abilities," he says.

Earlier, Communications Minister Kris Faafoi said the attacks on the NZX "did not bear the hallmarks of a state actor," going by briefings he had received from the GCSB

Advertisement
Advertise with NZME.

After a swathe of cyber-attacks on Australia during July, Australian PM Scott Morrison announced a $1.4 billion boost for cybersecurity spending - dwarfing Faafoi's single-digit millions here.

Faafoi did not immediately respond to a question about whether the GCSB's National Cyber Security Centre could get a further boost in light of the attack on the NZX and, more broadly, a 42 per cent increase in cyber incidents overall in the first half of this year, according to figures collated by Crown agency Cert NZ (the initials are for Computer Emergency Response Team).

Discover more

Shares

GCSB warns Kiwi businesses that cyber-attacks could get worse

30 Aug 11:36 PM
Business

Outlook for Thursday: MetService down again, sees more attacks

01 Sep 10:55 PM
Telecommunications

Cyber-security: Study finds most NZ small businesses tempting fate

08 Sep 05:30 AM
Business

Distressing video still on social media - TikTok, Facebook respond

08 Sep 10:51 PM

Cert NZ warned in November that a group of cyber-criminals, aping a Russian gang that has variously gone under the names Cozy Bear, Fancy Bear and the Armada Collective, was trying to extort New Zealand financial institutions with distributed denial of service (DDoS) attacks.

A DDoS attack sees thousands of computers hijacked, then used as "zombies" to overwhelm a website with connection requests, rendering it inaccessible to its regular users.

It was a DDoS attack that was aimed at the NZX.

The bourse has so far declined to confirm or deny if its attackers demanded money to stop their assault (which appeared to reanimated late Wednesday as the NZX site was again offline, albeit briefly).

This afternoon, Cert NZ deputy director Declan Ingram offered fresh details on the shifting nature of threats.

"Over the last six months we have seen an increase in the volume and sophistication of financially motivated cyberattacks in both New Zealand and overseas," he said.

Advertisement
Advertise with NZME.

"For instance, every day New Zealanders have been targeted by extortion and blackmail scams. This type of scam increased considerably during April, with reports to Cert NZ rising from less than 10 to over 170 per week.

Crown cyber-cop: Cert NZ deputy director Declan Ingram. His agency first warned NZ financial institutions about DDoS extortion attempts by a group aping Russia's Cozy Bear gang back in November.
Crown cyber-cop: Cert NZ deputy director Declan Ingram. His agency first warned NZ financial institutions about DDoS extortion attempts by a group aping Russia's Cozy Bear gang back in November.

"An attacker claims to have access to a person's webcam and has recorded them viewing adult material. The attacker threatens to share the alleged footage with person's contact list unless they pay a ransom.

"At the other end of the scale, we have seen highly disruptive ransomware attacks making multi-million dollar demands against businesses. Beyond the standard data encryption, some attackers have been stealing sensitive data and threatening to release it unless a ransom is paid."

If you're affected by ransomware Cert NZ recommends you don't pay the ransom, as it doesn't guarantee you'll get your data back. It could also put you at risk of further attacks if an attacker sees that you're willing to pay them, so they could target you again, Ingram said. Paying ransoms supports this kind of criminal activity.

Focus on prevention

Auckland University senior computer science lecturer Dr Rizwan Asghar told the Herald it was difficult to tell if the NZX attacker was a cyber-criminal or a state actor.

Both were good at imitating the other, and hiding their traces.

But he says it's easy to identify the immediate source of the attack: hapless people's vulnerable devices - older computers with inherently poor security, or new ones whose software has not been kept up to date.

"If ISPs co-ordinate together, then it might be possible to discover those vulnerable devices and potentially identify who exploited those devices," he says.

"But the fundamental challenge in such cases would be to collect information from countries where cybersecurity policies and compliance are poorly regulated."

Auckland University's Dr Rizwan Asghar says hackers are so good at covering their traces it's hard to tell a criminal from a state actor. Focus on preventing attacks, he says.
Auckland University's Dr Rizwan Asghar says hackers are so good at covering their traces it's hard to tell a criminal from a state actor. Focus on preventing attacks, he says.

NortonLifeLock security expert Mark Gorrie saw the NZX attacks as a profit-driven.

Today, like others, he had no idea on the identity of the attackers, but he did offer:

"When discussing a persistent targeted attack, the question of 'who did it?' always arises.

"Unfortunately, the attribution of cyberattacks is not an exact science and the question has become increasingly difficult and complex to answer.

"At NortonLifeLock we typically cluster attack incidents together and try to attribute them to known attack groups based on similarity of digital fingerprints, such as code similarities, shared tools and shared infrastructure.

"However, cybercriminals are getting more savvy at obfuscating their origins.

"There's no doubt New Zealand's top cybersecurity professionals are trying to figure out who attacked the NZX, media organisations and other companies - but we may never know who did it."

Metservice vs NZX

Earlier Kordia chief information security officer Hilary Walton said contingency planning was also key. Think about how you will do business, and communicate with your customers, if you are hit by a DDoS attack or ransomware.

Metservice was a star performer in this regard when it was hit by a DDoS attack last week. The forecasting service redirected customers to a backup site, which lacked videos and other frills, but provided basic weather information. By contrast, the NZX - whose trading platform was not under attack, but taken down when it had no website to fulfill its continuous disclosure obligations - took days to organise alternative channels.

Kordia chief information security officer Hilary Walton says prepare for the worst. Make contingency plans for communicating with clients in the event you are hit by a cyber attack. Photo / Supplied
Kordia chief information security officer Hilary Walton says prepare for the worst. Make contingency plans for communicating with clients in the event you are hit by a cyber attack. Photo / Supplied

Organisations should focus on prevention instead, Gorrie said.

"Ensure you, your employees and your business are using strong passwords, services like VPNs [virtual private networks] to encrypt important traffic, and reputable security software and services from trusted vendors."

Read more about the cyber-security spending gap between Australia and New Zealand, an insider's description of issues inside the GCSB and more in "Year of the Hacker".

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Agribusiness

Comvita forecasts another annual loss

15 Jun 11:39 PM
Premium
Business|companies

Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

15 Jun 11:27 PM
New Zealand

Mighty Ape boss fronts on account glitches

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Comvita forecasts another annual loss

Comvita forecasts another annual loss

15 Jun 11:39 PM

The mānuka honey company has cut staff by around 70 to save money and reduce debt.

Premium
Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

15 Jun 11:27 PM
Mighty Ape boss fronts on account glitches

Mighty Ape boss fronts on account glitches

Premium
Oil prices soar and local shares fall on fears of escalating Middle East conflict

Oil prices soar and local shares fall on fears of escalating Middle East conflict

15 Jun 10:43 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP