NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • Deloitte Fast 50
    • Generate wealth weekly
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In

Advertisement
Advertise with NZME.
Home / New Zealand

ManageMyHealth breach: Patients at risk of identity theft, extortion - experts

RNZ
4 Jan, 2026 07:07 PM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save
    Share this article
This ransom post screenshot is from a popular hacking forum.

This ransom post screenshot is from a popular hacking forum.

By Ruth Hill of RNZ

Thousands of patients caught up in the ManageMyHealth ransomware attack could be at risk of identity theft or extortion, cyber security experts are warning.

The hackers, calling themselves “Kazu”, posted on Sunday morning that unless the company paid a ransom within 48 hours, they would leak more than 400,000 files in their possession.

In a post on Telegram, the group purporting to be behind the breach said it had brought forward the deadline from January 15 in part because ManageMyHealth had responded faster than expected, but mainly to “put pressure on the company”.

“Their ignorance of our emails and messages, along with their failure to acknowledge users or explain exactly what happened, is the main issue. Many MMH users have been asking the company for an explanation, but they’ve either ignored them or responded with vague statements.”

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Kazu said it had opted for a low-ball ransom demand of $60,000 “to protect the data and quickly close the deal”.

“But it seems the company doesn’t care about their users’ data.”

The hackers indicated they were prepared to leak the “valuable” data just to make a point.

Advertisement
Advertise with NZME.

“We know exactly how valuable health data is and how sensitive it can be.

“Even if the company doesn’t pay the ransom, we can still find buyers for this data.

“To prove our claims and increase the chances of successful deals in the future, we decided to leak the data for free if they don’t pay the ransom.”

Kazu said they were “not a hacktivist group with political motives”.

“We’re doing this as a business. Our main goal is money and building a good reputation in the community.”

The hackers claimed to have successfully extracted ransom money from many healthcare companies in Asia and Africa over the past two months.

“Once the company pays, we send them a copy of the data, delete it from our servers and never post anything related to the company again.”

Patients at risk

Samples for potential “buyers” included clinical notes, lab results, vaccination records, medical photographs and personal identification details, including names, birth dates, addresses, emails and phone numbers.

IT consultant and Hornby community board member Cody Cooper was signed up to ManageMyHealth through his GP.

“My clinic has got 20,000 patients so there’s a real push for online. It’s seen as convenient, but patients don’t have a lot of choice.”

Advertisement
Advertise with NZME.

He went online to verify the veracity of the claims and was horrified by what he found.

“There’s people’s passports, there’s people’s ADHD documents from a psychiatrist, there’s pictures of people unclothed. It’s very personal data. And my concern as a patient would be, will someone blackmail people? Or try to extort them personally as well, if they don’t pay up?”

He also questioned why ManageMyHealth took so long to respond.

“The hack was published around 10pm on December 29, the MMH website notice appeared on the afternoon of December 31, but the site wasn’t taken offline until that evening.”

Furthermore, the company was taking too long to inform affected clinics and patients, he said.

“It should have been able to determine the extent of the breach relatively quickly. The fact that, days later there is no clear confirmation about what was accessed or copied is worrying.”

Advertisement
Advertise with NZME.

However, there was no guarantee that giving in to the hackers’ demands would solve the problem for MMH, he said.

“They may still release the data anyway, they may still contact people, we have no way of knowing if they will honour it.

“Furthermore, if that person is from a country with sanctions, there are laws and treaties that forbid that payment from being made legally as well.”

Patients were just collateral damage, he said.

“I will personally probably look to close my account. I can’t really have confidence in the system after this. Hopefully my clinic will find a solution that’s better.”

Hackers building their ‘brand’

Data journalist Keith Ng said the hackers appeared to be using ManageMyHealth to leverage a bigger payout from one of their other targets: Saudi Icon Ransom.

Advertisement
Advertise with NZME.

“They’re implying they’ve got their hands full and don’t want to be distracted by small fry here, that’s their explanation for wanting this over quickly – and if they don’t get their ransom they will release data for free.”

For Kazu, it was an exercise in brand management.

“They want to establish themselves as a ‘trustworthy’ ransomware group. By that they mean ‘If you pay us, we’ll delete the data and you’ll never hear from us again. If you don’t pay us, bad things will happen to you’.

“So they want to build up their business and use the New Zealand dataset to make an example out of, so people will take them more seriously in the future.”

Unfortunately, the ManageMyHealth breach was unlikely to be the result of a sophisticated hacking operation, Ng said.

“This is probably a couple of days’ work for a couple of people. It’s not like an elite hacking crew, it’s about volume and they want to make sure they’ve got targets on the hook all the time.

Advertisement
Advertise with NZME.

“They poke around and try to find common vulnerabilities, flaws, they’re really looking for low hanging fruit - and if they don’t find it, they move on quickly to the next target.”

Over and above the technical question of which part of ManageMyHealth’s system was not secure, the more important question was what processes it had in place, whether it was having regular independent security audits and taking action to fix the problems identified, he said.

“A business that sets itself up as a health information management system has a lot of incentive to do things right because when they fail, really catastrophic things like this happen, and it is an existential risk for them.

“So we should expect better from these businesses and the fact they let this one slip past them, they should be held accountable.”

In its public statements, ManageMyHealth appeared to be trying to minimise the scale of the problem, Ng said.

“They’re saying only 7% of users were affected, but 7% of 1.8 million is quite a big number. The other thing they’ve said is ‘only one component’ of the site is affected, not the core database. But it’s the kind of things in there – medical photos, test results – which make it so sensitive and damaging for people who are affected.

Advertisement
Advertise with NZME.

“It’s probably the worst data breach that I recall seeing in New Zealand so far.”

Aura Information Security’s Patrick Sharp said medical records were hugely valuable to criminals.

The Medibank ransomware attack in Australia in 2022 resulted in many thousands – “maybe even hundreds of thousands” of real financial crimes, he said.

“It’s quite likely that the 126,000 or so people affected – depending on the kind of information involved – may suffer at the hands of criminal gangs, lots of scams, blackmail, those kind of things.”

ManageMyHealth has been approached for comment.

Save
    Share this article

Latest from New Zealand

Sport

Whanganui shearer breaks nine-hour world record with 732 ewes

05 Jan 07:25 AM
New Zealand

Police continue search for tramper missing in South Island national park

05 Jan 06:46 AM
New Zealand

Debris on road: Two injured in Eleventh Ave crash

05 Jan 06:13 AM

Sponsored

The Bay’s secret advantage

07 Dec 09:54 PM
Advertisement
Advertise with NZME.

Latest from New Zealand

Whanganui shearer breaks nine-hour world record with 732 ewes
Sport

Whanganui shearer breaks nine-hour world record with 732 ewes

Simon Goss broke the record with less than 50 seconds to spare.

05 Jan 07:25 AM
Police continue search for tramper missing in South Island national park
New Zealand

Police continue search for tramper missing in South Island national park

05 Jan 06:46 AM
Debris on road: Two injured in Eleventh Ave crash
New Zealand

Debris on road: Two injured in Eleventh Ave crash

05 Jan 06:13 AM


The Bay’s secret advantage
Sponsored

The Bay’s secret advantage

07 Dec 09:54 PM
NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2026 NZME Publishing Limited
TOP