🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇳🇿 NZ › Other
Other sector · leaderboard
Own the Other leaderboard
The top banner across the Other overview and every Other record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

Air New Zealand — Airpoints

🇳🇿 Auckland · Air New Zealand · Record NZ-2021-0037
○ Reported — awaiting official confirmation
Reported — awaiting official confirmation. The facts below are drawn from the organisation's own disclosure and credible reporting. Figures are as reported; unknowns are labelled, not estimated by us.
People affected
Not disclosed
Breach date
2021-03
Regulator
NZ Privacy Commissioner
Trust tier
B · Reported

Data exposed

Airpoints member account details (names, contact and loyalty information) Media-reported

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

In March 2021 Air New Zealand notified Airpoints members of a credential-stuffing attack in which a third party used stolen credentials from elsewhere to access a number of member accounts [rnz-airnz]. The airline locked affected accounts and forced password resets. The number of accounts accessed was not precisely disclosed and is not estimated here.

Timeline

  • 2021-03 — Air NZ disclosed the Airpoints credential-stuffing attack [rnz-airnz].

Current status

Resolved; affected accounts secured. Figures are as reported. [rnz-airnz]

Why it matters

A classic credential-stuffing case — reused passwords, not an Air NZ system flaw, were the way in.

GGOVERN Tabletop Exercises · Govern house Strengthen your cyber resilience — rehearse the decisions that matter. Book a Discovery Call →