Cyber trends and insights with DUAL and Atmos
New Zealand's largest patient portal breach in late 2025 exposed sensitive health data of over 120,000 people, amplifying demands for robust cyber insurance amid escalating ransomware threats.
Key takeaways
- •A major December 2025 ransomware attack on Manage My Health compromised medical records including psychiatric diagnoses and domestic violence histories, triggering government reviews and highlighting vulnerabilities in private health data management.
- •Cyber insurance premiums in New Zealand and the region have stabilised or declined slightly in 2025 after prior hardening, creating a temporary buyer-friendly window before potential tightening in 2026 due to rising AI-driven threats and loss frequency.
- •Upcoming Privacy Amendment Act changes effective May 2026 introduce stricter indirect collection notification rules, increasing compliance burdens and potential liabilities that cyber policies must address to mitigate regulatory and financial risks.
Escalating Cyber Risks in New Zealand
New Zealand has faced a surge in significant cyber incidents, with the National Cyber Security Centre handling incidents daily that carry national harm potential. The late 2025 breach of Manage My Health, a widely used patient portal, stands out as one of the country's largest privacy violations. Hackers accessed and threatened to leak over 400,000 files containing highly sensitive personal health information from approximately 120,000 to 126,000 individuals, demanding a US$60,000 ransom with a January 2026 deadline. This incident exposed everyday Kiwis to risks of identity theft, blackmail, and discrimination based on medical histories.
Broader trends show cybercrime industrialising through ransomware-as-a-service models, lowering barriers for attackers and enabling scaled operations. State-sponsored actors target New Zealand entities beyond critical infrastructure, motivated by espionage or disruption. Financial losses from reported incidents reached $26.9 million in the year covered by the 2025 Cyber Threat Report, though actual costs including downtime and reputational damage likely far exceed this.
The cyber insurance market has shifted to more competitive conditions in 2025, with Pacific pricing declining around 10% and abundant capacity allowing better terms for buyers. However, signs of tightening emerged late 2025, driven by increased loss frequency, poor claims development in some areas, and emerging threats from AI adoption. Insurers scrutinise controls more closely, particularly around supply chains, third-party vendors, and basic hygiene like patching and multi-factor authentication.
Regulatory pressures add complexity. The Privacy Amendment Act 2025, with key provisions starting May 2026, mandates notifications for indirect collection of personal information under new Information Privacy Principle 3A, with exceptions but heightened accountability. This aligns with global trends toward stricter data rules, raising stakes for non-compliance through fines and litigation. Organisations face trade-offs: investing in resilience diverts resources from growth, while underinsurance risks catastrophic uncovered losses from ransomware or data breaches.
Non-obvious tensions include cybersecurity fatigue among leaders—despite nearly half of businesses reporting attacks in recent periods, fewer view it as a top 2026 threat—potentially leading to complacency just as AI accelerates attack sophistication and regulatory deadlines loom.
Sources
- https://www.dualinsurance.com/nz-en/cyber-insurance-webinar-rsvp-february-2026
- https://www.ncsc.govt.nz/insights-and-research/cyber-threat-reports/cyber-threat-report-2025
- https://www.infosecurity-magazine.com/news/new-zealand-orders-review-manage
- https://www.rnz.co.nz/news/national/584053/manage-my-health-data-breach-a-timeline-of-what-happened-and-everything-we-know-so-far
- https://www.aon.com/en/insights/articles/cyber-2026-evolving-threats-demand-strategic-leadership
- https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act
- https://thelionpartnership.com/news/australia-new-zealand-insurance-market-update-key-lines-early-2026
- https://www.insurancebusinessmag.com/nz/news/cyber/cyber-risk-investments-to-shape-2026-insurance-market--marsh-559563.aspx
You might also like
- Mar 4The inside cyber scoop: What brokers need to know in 2026
- Mar 17Franchises Under Fire: Securing Your Business from Cybersecurity Threats
- Mar 17Stop attacks before they spread with Okta’s Identity Threat Protection
- Mar 18Learning from Others’ Mistakes: Real Cyber-Breach Insights for NZ Businesses
- Apr 7Business cyber security awareness webinar