Safeware Glasswall APAC Partner
Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Control alignmentAPAC regulatory landscape
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongolia

More

Trust & certificationsInsightsPartnersAboutDocumentation Book a demo

Language

EnglishBahasa Indonesia日本語한국어Bahasa MelayuไทยTiếng Việt简体中文繁體中文

File-borne breach events · Oceania

New Zealand: documented file-borne breach events

New Zealand's largest health-sector cyber attack, the 2021 Waikato District Health Board ransomware incident, was publicly attributed by the board itself to an email attachment as the initial incursion.

Overview

What the record shows

The May 2021 ransomware attack on Waikato District Health Board was described at the time as the biggest cyber attack in New Zealand's history, and it is the country's clearest candidate for a file-borne record. The health board stated publicly that it believed the initial incursion came via an email attachment, and national reporting carried the same account.

The record here is the organisation's own stated assessment rather than a published forensic report, and the board's commissioned independent review was never released. This page reflects exactly that: the vector is presented as the board stated it, and no further.

Documented events

File-borne incidents in New Zealand

Most recent first. Every entry cites the public record it is drawn from.

  1. Phishing link in emailMedium impact

    Hutt City Council: A phishing email actioned by staff turned council mailboxes into an attack platform

    The March 2026 compromise was disclosed in a council report in April 2026. Five individuals had identity information compromised and 732 people may have had financial information exposed through email correspondence. The council reported the incident to the Office of the Privacy Commissioner and tightened security settings, monitoring and staff training; it declined a public records request for the full incident report.

    The documented vector. Phishing email actioned by a staff member, leading to takeover of several mailboxes. The council's incident report, as reported to its audit and risk subcommittee, records that the attack originated from a staff member responding to a phishing email, which gave attackers access to a small number of email accounts. Those accounts were then used to send further malicious email internally and externally.

    How this class of vector is removed

    This event shows the vector class propagating: once council mailboxes were sending, every recipient inside and outside the organisation received mail from a genuine government address. Rebuilding content to its format's known good specification and applying relay policy outcomes treats mail from a trusted internal sender exactly as it treats anything else, which is the property that matters once an account is speaking for the attacker. Glasswall does not claim to detect the deceptive link that began the chain, so the mapping is held at low confidence and rests on the file layer.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • government

    Source: 1News · Source: Cyber Daily

  2. Email attachmentHigh impact

    Waikato District Health Board: Hospital network taken down by ransomware the board attributed to an email attachment

    On 18 May 2021 ransomware disabled IT systems and phones across Waikato, Thames, Tokoroa, Te Kuiti and Taumarunui hospitals. Surgeries were postponed, radiation therapy was suspended with some cancer patients transferred, and services ran on paper for roughly four weeks. After the government declined to pay, attackers leaked patient, staff and financial data on the dark web on 29 June 2021. Full clinical restoration took until mid June 2021.

    The documented vector. Malicious email attachment (file type not published), the board's stated initial incursion. Waikato District Health Board stated publicly that it believed the initial incursion was via an email attachment, and contemporaneous national reporting described the malware as arriving in an email attachment as part of a phishing campaign. The vector stands as the board's own day one assessment: the published incident analysis has its malicious activity sections withheld in full, so the attribution was never independently confirmed on the public record, nor was it retracted.

    How this class of vector is removed

    The vector as the board stated it, a malicious email attachment, belongs to a class that is removed by deterministic CDR rebuild: inbound attachments are rebuilt to their format's known-good specification and stripped of active content before delivery, independent of any detection verdict on the specific ransomware family. The Email CDR Relay applies that rebuild on the mail path. The mapping is held at medium confidence because the vector rests on the organisation's stated assessment rather than a published forensic report.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • healthcare

    Source: eHealthNews.nz (HiNZ) · Source: RNZ

Scope

How to read this page

Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.

This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.

Elsewhere in the region

Other APAC territories

Files cross your boundary every day