{"id":216740,"date":"2026-01-04T19:46:08","date_gmt":"2026-01-04T19:46:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/216740\/"},"modified":"2026-01-04T19:46:08","modified_gmt":"2026-01-04T19:46:08","slug":"be-very-very-suspicious-neighbourly-breach-makes-users-vulnerable-expert","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/216740\/","title":{"rendered":"&#8216;Be very, very suspicious&#8217;: Neighbourly breach makes users vulnerable &#8211; expert"},"content":{"rendered":"<p><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/01\/4JVFT7S_Screenshot_2026_01_02_103825_jpg.jpeg\" width=\"1050\" height=\"659\" alt=\"Neighbourly is temporarily unavailable following a potential data breach.\"\/><\/p>\n<p class=\"photo-captioned__information\">\nThe website was initially shut down on New Year&#8217;s Day after the breach was uncovered but is now back online again.<br \/>\nPhoto: Screenshot\n<\/p>\n<p>People who have <a href=\"https:\/\/www.rnz.co.nz\/news\/national\/583057\/neighbourly-taken-down-after-claims-of-data-breach\" rel=\"nofollow noopener\" target=\"_blank\">had their personal information stolen<\/a> from the Stuff-owned Neighbourly platform could be vulnerable to online threats, a cyber security expert says.<\/p>\n<p>Neighbourly has lost names, email address, private messages, posts and GPS locations which have been put <a href=\"https:\/\/www.rnz.co.nz\/news\/national\/583124\/neighbourly-users-private-information-up-for-sale-on-dark-web-after-a-breach\" rel=\"nofollow noopener\" target=\"_blank\">up for sale on the dark web<\/a>.<\/p>\n<p>The website was initially shut down on New Year&#8217;s Day after the breach was uncovered but is now back online again.<\/p>\n<p>Neighbourly has told members it will look to get a court injunction, but it is satisfied the breach was quickly contained.<\/p>\n<p>It surfaced around the same time of another <a href=\"https:\/\/www.rnz.co.nz\/news\/national\/583170\/managemyhealth-breach-patients-at-risk-of-identity-theft-extortion-experts\" rel=\"nofollow noopener\" target=\"_blank\">major breach with privately-owned Manage My Health<\/a>, which more than 120,000 patient files compromised.<\/p>\n<p>&#8220;The most concerning thing about the Neighbourly one is that there is GPS information in there, which I assume is people&#8217;s homes,&#8221; Patrick Sharp, general manager at Aura Information Security told RNZ.<\/p>\n<p>&#8220;So that, correlated with other information that&#8217;s out on the internet might provide some kind of attack opportunity for an attacker.&#8221;<\/p>\n<p>Sharp said the taking of the information was &#8220;absolutely&#8221; a concern.<\/p>\n<p>&#8220;After the Medibank breach in Australia in 2022 there were tens, or maybe hundreds of thousands of actual financial crimes that resulted from the information stolen in that breach&#8230; so this is probably the beginning,&#8221; he said.<\/p>\n<p>&#8220;Bear in mind as well that the people who are impacted by the ManageMyHealth breach and the Neighbourly breach are potentially people who are quite vulnerable and don&#8217;t understand how to protect themselves.<\/p>\n<p>&#8220;So if a member of your family, an elderly person in your family, or anything like that tells you that they&#8217;re affected then you should probably help them try to understand or vet any kinds of unsolicited contact they get from anyone as well,&#8221; Sharp said.<\/p>\n<p>&#8220;I think more than anything they need to be suspicious, and if someone calls you out of the blue or you get an email which you&#8217;re not expecting, you should just be very, very suspicious about it.&#8221;<\/p>\n<p>Sharp said cyber attacks rise toward the end of the year, and websites or platforms growing in size an expose vulnerabilities.<\/p>\n<p>&#8220;The reality is that websites are very complex systems and they go through a lot of change as they update new features and so on, and so when they do that, the possibilities of introducing new vulnerabilities into those websites is very, very possible,&#8221; Sharp said.<\/p>\n<p>&#8220;And so unless they maintain a high degree of security during the development process and the update process, those vulnerabilities can be quite impactful,&#8221; he said.<\/p>\n<p>&#8220;In practice one it&#8217;s out there, it&#8217;s out there,&#8221; Sharp said.<\/p>\n<p>Neighbourly earlier said it took its data privacy responsibilities seriously and had contacted members directly.<\/p>\n<p>On its website, it promotes itself with the tag line &#8220;your personal information is safe&#8221;.<\/p>\n<p>Lives could be put at risk<\/p>\n<p>Gorilla Technology chief executive Paul Spain said the Neighbourly data breach was &#8220;really significant&#8221;.<\/p>\n<p>&#8220;There&#8217;s a large amount of data involved and it impacts somewhere between 800,000 and one million people potentially,&#8221; he said.<\/p>\n<p>&#8220;The size of the breach suggests that it is certainly a possibility for a large percentage of those people who have their data taken.&#8221;<\/p>\n<p>Spain also said the taking of GPS co-ordinates was a concern and would be concerning for some people.<\/p>\n<p>&#8220;I guess the reality is when there&#8217;s this many people impacted then probably most folks won&#8217;t directly be impacted, but you just don&#8217;t know whether you&#8217;re going to get targeted with some sort of a scam where they know some personal information and they are able to take advantage of you,&#8221; he said.<\/p>\n<p>&#8220;And if that ends up leaking out on the dark web and becomes available to anybody that could actually put, in some cases, put people&#8217;s lives at risk.&#8221;<\/p>\n<p>He said a court injunction would be to stop people who are New Zealand-based from referencing the information.<\/p>\n<p>&#8220;Because once it&#8217;s available out there, of course, anybody can get it and so you could just do a court injunction that says &#8216;hey, this is private information and shouldn&#8217;t be published through through legitimate platforms&#8217;,&#8221; he said.<\/p>\n<p>&#8220;But it&#8217;s still available unfortunately to anyone that chooses to pay for it or retrieve the portions of it that might be leaked for free.&#8221;<\/p>\n<p>Spain described the Neighbourly breach as a wake-up call.<\/p>\n<p>&#8220;And unfortunately we seem to have, I think, a kind of &#8216;she&#8217;ll be right, mate&#8217; attitude to cyber security in New Zealand for a lot of organisations, and it&#8217;s surprising, you know, how many organisations don&#8217;t get regular cyber security audits carried out or have a good level of clarity around where their risks are and what they can do to reduce those risks.<\/p>\n<p>&#8220;You know, an organisation of the scale of stuff.co.nz who own Neighbourly, they should be at the scale to make sure that they&#8217;re keeping on top of these things.&#8221;<\/p>\n<p><a href=\"https:\/\/radionz.us6.list-manage.com\/subscribe?u=211a938dcf3e634ba2427dde9&amp;id=b3d362e693\" rel=\"nofollow noopener\" target=\"_blank\">Sign up for Ng\u0101 Pitopito K\u014drero<\/a>, a daily newsletter curated by our editors and delivered straight to your inbox every weekday.<\/p>\n","protected":false},"excerpt":{"rendered":"The website was initially shut down on New Year&#8217;s Day after the breach was uncovered but is now&hellip;\n","protected":false},"author":2,"featured_media":212324,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[48,138,47,111,43,139,69,49,46,44,45],"class_list":{"0":"post-216740","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"tag-audio","9":"tag-business","10":"tag-current-affairs","11":"tag-new-zealand","12":"tag-news","13":"tag-newzealand","14":"tag-nz","15":"tag-podcasts","16":"tag-public-radio","17":"tag-radio-new-zealand","18":"tag-rnz"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/216740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=216740"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/216740\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/212324"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=216740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=216740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=216740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}