🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇳🇿 NZ › Finance
Finance sector · leaderboard
Own the Finance leaderboard
The top banner across the Finance overview and every Finance record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

Thankyou Payroll — Metabase Global Incident

🇳🇿 New Zealand · Thankyou Payroll · Record NZ-2026-0003
● Confirmed
People affected
Not disclosed
Breach date
2026-08-06
Regulator
NZ-Privacy-Commissioner
Trust tier
A · Confirmed

Data exposed

Names Confirmed
IRD (tax file) numbers Confirmed
Email addresses Confirmed
Physical addresses Confirmed
Bank account details Confirmed
Payment histories Confirmed

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

On September 10, 2026, Thankyou Payroll disclosed that it had been caught in a global data security incident involving Metabase, an open-source business intelligence platform it self-hosted for internal reporting. [rnz-news] The attack exploited CVE-2026-72898, a critical SQL injection vulnerability (CVSS 10.0) that Metabase disclosed and patched on August 6, 2026. [company-disclosure] Thankyou Payroll’s instance was not updated, leaving it exposed from August 6 through September 10, 2026. The company notified the Office of the Privacy Commissioner immediately upon discovery. [rnz-news]

Data exposed

Unauthorised access was confirmed to:

  • Names, IRD numbers, email addresses, physical addresses, bank account details, and payment histories [company-disclosure]

Passwords and credit card numbers were not compromised. [rnz-news]

Timeline

  • August 6, 2026 — Metabase publishes critical security advisory and patch for CVE-2026-72898 (SQL injection, CVSS 10.0). [company-disclosure]
  • August 6–September 10, 2026 — Unpatched Metabase instance at Thankyou Payroll exploited by attackers; data accessed. [company-disclosure]
  • September 10, 2026 — Thankyou Payroll discovers breach and notifies Office of Privacy Commissioner. [rnz-news]

Regulatory outcome

The breach was notified to the Office of the Privacy Commissioner under New Zealand’s Privacy Act 2020 mandatory notification regime (72-hour notification requirement). Investigation status: ongoing. [company-disclosure]

Why it matters

This incident exemplifies the cascading risk of third-party infrastructure failures. Metabase is widely deployed across thousands of organizations — the same vulnerability hit dozens of companies simultaneously. The lesson is multi-layered: for SaaS and self-hosted deployments, patch timing is not optional; for payroll and HR systems specifically, the data at risk (tax file numbers, bank details, employment records) reaches the threshold of serious harm immediately. Organisations reliant on tools with known critical vulnerabilities face regulatory liability even when the tool itself is third-party.

GGOVERN Tabletop Exercises · Govern house Rehearse the breach before it reaches the balance sheet. Book a Discovery Call →