What happened
On September 10, 2026, Thankyou Payroll disclosed that it had been caught in a global data security incident involving Metabase, an open-source business intelligence platform it self-hosted for internal reporting. [rnz-news] The attack exploited CVE-2026-72898, a critical SQL injection vulnerability (CVSS 10.0) that Metabase disclosed and patched on August 6, 2026. [company-disclosure] Thankyou Payroll’s instance was not updated, leaving it exposed from August 6 through September 10, 2026. The company notified the Office of the Privacy Commissioner immediately upon discovery. [rnz-news]
Data exposed
Unauthorised access was confirmed to:
- Names, IRD numbers, email addresses, physical addresses, bank account details, and payment histories [company-disclosure]
Passwords and credit card numbers were not compromised. [rnz-news]
Timeline
- August 6, 2026 — Metabase publishes critical security advisory and patch for CVE-2026-72898 (SQL injection, CVSS 10.0). [company-disclosure]
- August 6–September 10, 2026 — Unpatched Metabase instance at Thankyou Payroll exploited by attackers; data accessed. [company-disclosure]
- September 10, 2026 — Thankyou Payroll discovers breach and notifies Office of Privacy Commissioner. [rnz-news]
Regulatory outcome
The breach was notified to the Office of the Privacy Commissioner under New Zealand’s Privacy Act 2020 mandatory notification regime (72-hour notification requirement). Investigation status: ongoing. [company-disclosure]
Why it matters
This incident exemplifies the cascading risk of third-party infrastructure failures. Metabase is widely deployed across thousands of organizations — the same vulnerability hit dozens of companies simultaneously. The lesson is multi-layered: for SaaS and self-hosted deployments, patch timing is not optional; for payroll and HR systems specifically, the data at risk (tax file numbers, bank details, employment records) reaches the threshold of serious harm immediately. Organisations reliant on tools with known critical vulnerabilities face regulatory liability even when the tool itself is third-party.