Rotorua Daily Post
  • Rotorua Daily Post home
  • Latest news
  • Business
  • Opinion
  • Lifestyle
  • Property
  • Sport
  • Video
  • Death notices
  • Classifieds

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • On The Up
  • Business
  • Opinion
  • Lifestyle
    • All Lifestyle
    • Residential property listings
  • Property
    • All Property
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
  • Rural
  • Sport

Locations

  • Tauranga
  • Te Puke
  • Whakatāne
  • Rotorua
  • Tokoroa
  • Taupō & Tūrangi

Media

  • Video
  • Photo galleries
  • Today's Paper - E-Editions
  • Photo sales

Weather

  • Rotorua
  • Tauranga
  • Whakatāne
  • Tokoroa
  • Taupō

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Rotorua Daily Post

Pinnacle Health hack: Sensitive files posted to the dark web include 'confidential' report

By Chris Keall & Rachel Maher
NZ Herald·
9 Oct, 2022 04:00 PM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Sensitive files posted to the dark web, Auckland’s new mayor gets to work and police on the scene in Wattle Downs in the latest NZ Herald headlines. Video / NZ Herald

Sensitive patient files and high-level data stolen in a cyber attack on a major primary health provider have been posted to the dark web by a ransomware group with Russian links, the Herald can reveal.

In a statement last night, Pinnacle Midlands Health Network — which operates dozens of North Island GP practices — confirmed the upload of stolen material to the net, following a "cyber incident" last week.

While the number of affected patients has not been made public, initial reports suggested hackers may have had access to as many as 450,000 people's information.

Justin Butcher, CEO of Pinnacle Incorporated, told the Herald information illegally obtained was uploaded to the internet by "malicious actors".

The information and data related to past and present patients and customers of the Pinnacle group in the Waikato, Lakes, Taranaki and Tairawhiti districts. It also includes Primary Health Care Ltd (PHCL) practices from across Taranaki, Rotorua, Taupō-Tūrangi, Thames-Coromandel and Waikato.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

The information in the breach includes high-level data related to the use of hospital services, claiming information related to services that Pinnacle provides, and information sent to practices around immunisation and screening status of individual patients.

"Over the past 24 hours, we were notified by our security experts that the data taken from our IT platform had been released by malicious actors," Butcher confirmed.

"We acknowledge that this will be concerning to our patients and their whānau, and we are taking this seriously, our immediate focus is on supporting people who may have been impacted, and working with the authorities to ensure we are doing everything we need to be."

Advertisement
Advertise with NZME.
Pinnacle chief executive Justin Butcher said investigations were still under way but he believed attackers accessed information that could include commercial and personal details. Photo / Supplied
Pinnacle chief executive Justin Butcher said investigations were still under way but he believed attackers accessed information that could include commercial and personal details. Photo / Supplied

While Pinnacle does not hold GP notes and consultation records, Butcher said the company "now have a much clearer understanding of the breadth of stolen data".

"This is extremely unfortunate, and we are gutted as this impacts our whānau also. Cyber incidents like this are a constant threat, and while they are the doing of malicious actors, we feel for everyone who may have been affected."

Pinnacle has been in contact with police and the Office of the Privacy Commissioner. Police would not comment yesterday.

Sources have told the Herald that a ransomware gang called ALPHV, also known as Black Cat, published a patient assessment, marked "confidential", from a clinic in the Pinnacle group.

It also published a financial memo about budget goals, a spreadsheet and a scan of a passport, which appeared to be taken from Pinnacle's system, among other files.

The Herald did not access Pinnacle files posted online by ALPHV, but was shown screen grabs by a source in the cybersecurity industry.

ALPHV, also known as Black Cat, published a patient assessment, marked confidential, from a clinic in the Pinnacle group. Photo / 123rf
ALPHV, also known as Black Cat, published a patient assessment, marked confidential, from a clinic in the Pinnacle group. Photo / 123rf

"Like other ransomware operations, ALPHV uses the threat of releasing data as additional leverage to extort payment," Brett Callow, a threat analyst with NZ-based cybersecurity firm Emisoft, told the Herald.

"Healthcare sectors the world over have been increasingly targeted by for-profit cybercriminals in recent years."

Groups like ALPHV often offer a "taster" of data on the dark web, either to pressure a victim into paying a cyber-ransom or, in some cases, to solicit bids for data.

Offshore, there have been cases of hackers trying to blackmail individual patients, as well as to extort a payment from a healthcare provider.

Advertisement
Advertise with NZME.

ALPHV hit headlines in August for its attacks on energy companies and has pioneered searchable, online databases of stolen data as a method of turning the screws on victims.

Unit 42, a division of Nasdaq-listed cybersecurity giant Palo Alto Networks, whose board includes former Prime Minister Sir John Key, has linked ALPHV members to Russia, saying the group communicates to its members or affiliates in the Russian language and is known to operate on Russian cybercrime forums.

Image / 123rf
Image / 123rf

In May, GCSB director-general Andrew Hampton warned New Zealand could be targeted by pro-Putin hackers.

If the first leak gets no response, it is typically followed by more sensitive data being spilled online.

The information is offered to cybercriminals in the know. The Pinnacle files were posted to the dark web, which is not searchable by Google, or even accessible via a regular web browser. Special software is required.

On October 4, Pinnacle, which runs a network of 87 GP practices, said a "cyber incident" affected some IT services at offices and practices in Taranaki, Rotorua, Taupō-Tūrangi, Thames-Coromandel and Waikato.

Advertisement
Advertise with NZME.

The breach took place on September 28.

At an October 4 press conference, Pinnacle would not say whether it was negotiating with the hackers.

Butcher then said he believed the stolen information could include commercial and personal details.

Later the same day, he told RNZ's Checkpoint the hacked system did not contain clinical notes.

The patient file posted by ALPHV is labelled "Confidential neuropsychological report".

It is from a provider outside the Pinnacle group and details assessments related to a person's ACC claim.

Advertisement
Advertise with NZME.

It was for a patient in the Waikato and part of a collection of files ALPHV said were from Pinnacle.

Cybersecurity expert Alastair Millar, from Aura Information Security, told RNZ the potential for identity theft was a worry for the people affected but Pinnacle had been open about it and was pointing people towards support service ID Care and tools available to try protect their identity.

But Millar said it was possible the hackers could be seeking a large financial sum in exchange or to sell the data on the dark web, as was done in a hack on Waikato District Health Board last year.

Photo / 123rf
Photo / 123rf

With people's NHI number and contact information, hackers could obtain credit cards, take out loans or buy gift cards, he said.

Police advise against paying cyber ransoms.

They say there is no guarantee stolen data will be destroyed or returned (or frozen systems unlocked) and that payments both fund and incentivise such crimes.

Advertisement
Advertise with NZME.

However, in New Zealand it is not illegal to pay a cyber-ransom.

The Government says taking such a step would criminalise victims.

Pinnacle is also working with the Ministry of Justice-backed ID Care, which offers assistance to those worried they have been the victim of identity theft, and can walk people through the process of freezing credit records, Butcher said.

ID Care has set up a page dedicated to the Pinnacle cyber breach.

People can also call ID Care's Case Management Centre on 0800 121 068.

Save

    Share this article

Latest from Rotorua Daily Post

Rotorua Daily Post

Rotorua chef denies arson of his own home

19 Jun 06:00 AM
Rotorua Daily Post

How to celebrate Matariki in Rotorua

19 Jun 05:01 AM
Rotorua Daily Post

Watch: 'Hand of God' controversy in schoolboy rugby scrum

19 Jun 04:29 AM

Jono and Ben brew up a tea-fuelled adventure in Sri Lanka

sponsored
Advertisement
Advertise with NZME.

Latest from Rotorua Daily Post

Rotorua chef denies arson of his own home

Rotorua chef denies arson of his own home

19 Jun 06:00 AM

The fire took place around midnight and took firefighters three hours to control.

How to celebrate Matariki in Rotorua

How to celebrate Matariki in Rotorua

19 Jun 05:01 AM
Watch: 'Hand of God' controversy in schoolboy rugby scrum

Watch: 'Hand of God' controversy in schoolboy rugby scrum

19 Jun 04:29 AM
Cold showers, decontamination for workers at scene of truck crash

Cold showers, decontamination for workers at scene of truck crash

19 Jun 04:15 AM
Help for those helping hardest-hit
sponsored

Help for those helping hardest-hit

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • Rotorua Daily Post e-edition
  • Manage your print subscription
  • Manage your digital subscription
  • Subscribe to Herald Premium
  • Subscribe to the Rotorua Daily Post
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • Rotorua Daily Post
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP