It said it took steps to contain the incident when it became aware of what had happened.
The company said the person who accessed the data claimed to have obtained 1.6 million contacts but it refuted that claim because it did not have that many on its database.
It said third-party platform forensic investigators said this number related to duplicate entries.
“We recognise the trust our clients place in us and regret any concern this incident may cause. Since becoming aware of the incident, our focus has been on containing the issue, understanding exactly what occurred, and working with independent cyber security specialists to protect client information. We remain committed to transparency and will continue to provide updates as deemed necessary,” New Zealand managing director Mark Harris said.
In an email to clients, it said there could be some cases where information stored within an open-text notes field could be deemed sensitive and have been accessed. It said anyone affected in that way would be contacted directly.