Waikato Herald
  • Waikato Herald home
  • Latest news
  • Sport
  • Business
  • Rural
  • Lifestyle
  • Lotto results

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • On The Up
  • Sport
  • Business
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
  • Lifestyle
  • Lotto results

Locations

  • Hamilton
  • Coromandel & Hauraki
  • Matamata & Piako
  • Cambridge
  • Te Awamutu
  • Tokoroa & South Waikato
  • Taupō & Tūrangi

Weather

  • Thames
  • Hamilton
  • Tokoroa
  • Taumarunui
  • Taupō

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Waikato News

New World customers warned after ‘password spraying’ attack

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
12 Jul, 2025 02:39 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

In a "password spraying" attack, a scammer uses previously compromised passwords or automated tools to try lots of common weak passwords. Image / Herald graphic

In a "password spraying" attack, a scammer uses previously compromised passwords or automated tools to try lots of common weak passwords. Image / Herald graphic

New World Clubcard members are being asked to change their online passwords after a cyber attack.

One expert is questioning why customers were allowed to set weak online passwords and have “0000″ passwords on their physical cards.

“Foodstuffs North Island and Foodstuffs South Island have identified a recent attempt by scammers to gain unauthorised access to a limited number of New World Clubcard accounts,” a spokesman for New World owner Foodstuffs said.

“This activity is consistent with what’s known as a ‘password spraying’ attack, where commonly used or previously compromised passwords are tested across many accounts.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

“We want to reassure our customers that Foodstuffs’ systems have not been breached or compromised in any way.

“The issue has arisen where some customers’ passwords have been successfully guessed by scammers using automated tools.”

The spokesman said no personal credit card data has been compromised: “Foodstuffs never stores full [credit] card numbers.”

However, a New World Clubcard account can have “New World dollars” loaded to it, earned under a rewards scheme, that can be used to buy groceries.

Advertisement
Advertise with NZME.

“As a precaution, we have temporarily disabled the ability to redeem New World dollars on affected Clubcard accounts and removed stored payment tokens linked to them,” the spokesman said.

Citing security, the spokesman would not answer questions about whether scammers had been able to order groceries, whether refunds had been paid if they had, or how many accounts were affected.

“To restore access and ensure ongoing protection, we are asking affected customers to reset their passwords, choosing a strong and unique passphrase,” the spokesman said.

Expert’s concerns

Hamish Krebs, a cybersecurity incident response expert with security firm CyberCX, who also happens to be a New World customer, got the Foodstuffs email this morning as a New World Clubcard customer. Like a number of other customers, he was told his account was not affected but that in keeping with “security best practice” he should update his account anyway.

In Krebs’ view, any transactional site should require a strong online password from the get-go.

Physical New World Club Cards also had a 0000 default PIN number - and some never changed it.

“I can confirm New World Dollars have been disabled for those customers’ cards too,” the Foodstuffs spokesman said.

Another concern for Krebs: He said he could also only find one “multi-factor authentication” (MFA) option in the New World Clubcard app – to have a code sent to a cellphone number. He said the drawback was that once logged into a Clubcard account, a scammer could change the associated cellphone number to their own.

Krebs said a scammer who accessed a Clubcard account could spend a customer’s New World reward dollars – but because a credit card could be tied to an account, they could also spend beyond the rewards balance “and buy $500 worth of beer and wine and get that delivered to any address or click and collect”.

As a New World customer, I placed an order through New World’s app, going beyond my Clubcard rewards dollar balance of $10.73 to place a $19.73 click-and-collect order with the balance charged to my stored credit card without a three-digit security code being requested.

Advertisement
Advertise with NZME.

Once logged into the New World Clubcard website, items could also be added to an order – and charged to a saved credit card – without a security code being requested.

Ability to charge but credit card details not visible

While it seems the scammers had the potential ability to charge New World purchases to the credit card associated with a compromised account, they could not see the card number, name, expiry date or three-digit security number.

“We store an encrypted token, not credit card details,” the Foodstuffs spokesman said.

“That allows the credit card to be used in transactions but ensures the card details themselves are not at risk.

“For the customers successfully targeted by the attackers, we deleted the encrypted tokens, ensuring that if the attackers attempted to use their account to order online [once the breach had been discovered], they would not be able to make a payment, thus protecting our customers.”

Change your password

“To restore access and ensure ongoing protection, we are asking affected customers to reset their passwords, choosing a strong and unique passphrase,” the Foodstuffs spokesman said.

Advertisement
Advertise with NZME.

“We are closely monitoring for any further malicious activity and working alongside external cybersecurity experts to further reinforce our defences.

“We apologise for the inconvenience. Protecting our customers’ privacy, data and trust is a top priority, and we are taking every step to respond quickly.”

Foodstuffs’ password recommendations

Foodstuff recommends customers follow the guidelines below when resetting their New World Clubcard password.

CyberCX’s Krebs said he agreed with all the guidelines, including the recommendation to “use at least 12 characters” but that as of this morning, after receiving Foodstuffs’ warning email, he still had the option in the New World Clubcard app to set a less secure six-character password.

  • Use at least 12 characters. Longer passwords are harder to crack
  • Mix character types
  • Include uppercase, lowercase, numbers, and at least one of these symbols (!@$%^&*()_+=-{};:’“,.<>?|~`)
  • Avoid common words and patterns
  • Don’t use easily guessed words like password, 123456, or qwerty
  • Don’t use personal information
  • Avoid names, birthdays or addresses
  • Use passphrases
  • Combine unrelated words into a phrase (eg BlueTiger!Drinks7Coffee)
  • Don’t reuse passwords across different accounts

Foodstuffs ‘doing the right thing’

A second cyber security expert was more positive in his take on Foodstuffs’ response.

“This is a common form of attack in which passwords have been lost in another breach, or attackers are simply trying to guess common passwords,” Aura Information Security general manager Patrick Sharp said.

Advertisement
Advertise with NZME.

“It is not a data breach, and is not caused by a weakness in New World’s systems.”

A password manager, such as LastPass or Bitwarden, is a good way to manage complex passwords on many sites effectively, Sharp said. The latest web browsers also act as password managers, suggesting strong passwords then remembering them for you (as long as you remember your master password to access your “vault” of logons).

“Foodstuffs are doing the right thing communicating proactively about this – they’ve given good detail and great advice,” Sharp said.

Chris Keall is an Auckland-based member of the Herald’s business team. He joined the Herald in 2018 and is the technology editor and a senior business writer.

Save

    Share this article

Latest from Waikato News

Sport

Waikato boxers off to Australia for Commonwealth Games qualifier

Waikato Herald

'I can't believe it': Maxwell's thrilling comeback at MTB World Cup

Waikato Herald

Family seeks answers over woman's death on Mt Ruapehu


Sponsored

Solar bat monitors uncover secrets of Auckland’s night sky

Advertisement
Advertise with NZME.

Latest from Waikato News

Waikato boxers off to Australia for Commonwealth Games qualifier
Sport

Waikato boxers off to Australia for Commonwealth Games qualifier

The Queensland International Golden Gloves Tournament is being held this week.

14 Jul 02:21 AM
'I can't believe it': Maxwell's thrilling comeback at MTB World Cup
Waikato Herald

'I can't believe it': Maxwell's thrilling comeback at MTB World Cup

13 Jul 10:43 PM
Family seeks answers over woman's death on Mt Ruapehu
Waikato Herald

Family seeks answers over woman's death on Mt Ruapehu

13 Jul 09:12 PM


Solar bat monitors uncover secrets of Auckland’s night sky
Sponsored

Solar bat monitors uncover secrets of Auckland’s night sky

06 Jul 09:47 PM
NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • Waikato Herald e-edition
  • Manage your print subscription
  • Manage your digital subscription
  • Subscribe to Herald Premium
  • Subscribe to the NZ Herald newspaper
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • Waikato Herald
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP