🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇳🇿 NZ › Government
Government sector · leaderboard
Own the Government leaderboard
The top banner across the Government overview and every Government record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

Reserve Bank of New Zealand (Accellion FTA)

🇳🇿 Wellington · Reserve Bank of New Zealand — Te Pūtea Matua · Record NZ-2021-0009
● Confirmed
People affected
Not disclosed
Breach date
2020-12
Regulator
NZ Privacy Commissioner
Trust tier
A · Confirmed

Data exposed

Commercially and personally sensitive information held in a third-party file-transfer service Company-confirmed

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

In late 2020 / early 2021 the Reserve Bank of New Zealand disclosed that a third-party file-transfer application (Accellion FTA) it used had been illegally accessed, exposing commercially and personally sensitive information held in that service [rbnz]. The Bank commissioned an independent review and reported the incident to authorities. The number of individuals affected was not officially quantified and is not estimated here.

Timeline

  • 2020-12 — Accellion FTA file-transfer service compromised (global supply-chain attack) [rbnz].
  • 2021-01 — RBNZ publicly disclosed the breach and began its response [rbnz].

Current status

Resolved, following an independent review and remediation. [rbnz]

Why it matters

A textbook supply-chain breach: the Bank itself wasn’t hacked directly — a widely-used file-transfer tool was — showing how third-party software can expose even a central bank.

GGOVERN Tabletop Exercises · Govern house Brief the minister with a decision you’ve already rehearsed. Book a Discovery Call →