🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
🎓 For students & practitioners

Understand the breaches — not just read about them.

Every record in the register is a real-world case study. This section explains the concepts behind them, the frameworks that govern them in New Zealand, Australia and abroad, and exactly where our data comes from — and where it doesn't.

Advertising
Your brand, in front of the right people
Run-of-site leaderboard — the register, by-sector directory, Learn and Alerts.
Enquire → breach@govern.co.nz

Start here

Key concepts you'll see across the register
🗄️
Data breach
Unauthorised access to, or disclosure of, personal or sensitive information.
Seen in: every record
📤
Exfiltration
The attacker copies data out of the network — the step that turns an intrusion into a breach.
Seen in: Australian Clinical Labs
🔒
Ransomware
Malware that encrypts systems for extortion — increasingly paired with data theft ("double extortion").
Seen in: Langley Twigg
🎣
Phishing & credential theft
Tricking staff into handing over logins — still the most common entry point.
The most common first step
🔗
Supply-chain / third-party
The victim is breached through a vendor or IT provider, not directly.
Seen in: Partnered Health
🕳️
Dark-web leak
Stolen data published or sold on hidden forums when a ransom isn't paid.
Seen in: Langley Twigg
🪪
PII
Personally identifiable information — names, IDs, Medicare/licence numbers, health data.
Seen in: Partnered Health
🔔
Notifiable breach
A breach serious enough that the law requires notifying the regulator and those affected.
The trigger for most records
⚖️
Civil penalty
A court-ordered fine for failing privacy obligations — e.g. Australia's first, A$5.8M.
Seen in: Australian Clinical Labs

The rulebooks

National & international frameworks that govern this space
🇳🇿 New Zealand 🇦🇺 Australia 🌐 International
NZISM
New Zealand Information Security Manual · GCSB / NCSC · v3.9
NZ government's technical security standard — the baseline controls agencies and many businesses use.
nzism.gcsb.govt.nz →
Privacy Act 2020
Office of the Privacy Commissioner · 13 Information Privacy Principles
Sets how organisations must handle personal information, and mandatory notification of serious breaches.
www.privacy.org.nz →
NCSC (incorporating CERT NZ)
Lead operational cyber agency · merger completed 2024
Where cyber incidents are now reported in NZ, and the source of the quarterly Cyber Security Insights.
www.ncsc.govt.nz →
Protective Security Requirements
NZ Government protective security policy
The broader framework covering governance, personnel, physical and information security.
www.protectivesecurity.govt.nz →
Australian Government ISM
Australian Signals Directorate / ACSC · "the ISM"
Australia's equivalent of NZISM — the cyber security controls framework for systems and data.
www.cyber.gov.au →
Essential Eight
ACSC · mitigation strategies + maturity model
Eight prioritised controls (patching, MFA, backups…) that prevent most incidents.
www.cyber.gov.au →
Privacy Act 1988 + APPs
OAIC · 13 Australian Privacy Principles
Governs personal information handling; civil penalties for serious breaches now reach A$50M.
www.oaic.gov.au/privacy/australian-privacy-principles →
Notifiable Data Breaches (NDB)
OAIC · mandatory reporting scheme
Requires notifying the OAIC and affected people of eligible breaches — the source of much AU data.
www.oaic.gov.au/privacy/notifiable-data-breaches →
ISO/IEC 27001
International standard · ISMS certification
The globally recognised standard for an Information Security Management System.
NIST Cybersecurity Framework
US NIST · CSF 2.0
A widely adopted risk-based framework for structuring a security programme.
GDPR
European Union · General Data Protection Regulation
The benchmark privacy law that shaped notification regimes worldwide.
SOC 2 · PCI DSS
AICPA · PCI Security Standards Council
SOC 2 attests to a provider's controls; PCI DSS governs how card data must be protected.

Explore ATT&CK yourself

The official tools & data behind the framework

MITRE ATT&CK® is a free, globally-used knowledge base of how attackers actually operate — the shared vocabulary the security world uses to name and compare techniques. These are MITRE's own tools for working with it, all free and open. Each box says, plainly, what it's for.

ATT&CK Navigator
Explore & annotate the matrix in your browser
Colour in the techniques you can detect or prevent, layer on a threat group's known behaviours, and export the picture. The standard way teams visualise their coverage — and their gaps.
Open the tool →
ATT&CK in STIX 2.1
The machine-readable dataset — the source of truth
Every technique, threat group, piece of software and mitigation as structured data. This is the canonical download that the other tools read from, updated each ATT&CK release.
View on GitHub →
mitreattack-python
Work with ATT&CK in code
MITRE's official Python library for querying and processing the dataset — the practical starting point for any automation, mapping or analysis on top of ATT&CK.
View on GitHub →
ATT&CK Workbench
Run and extend your own copy of ATT&CK
A self-hosted app to explore the knowledge base and add your own techniques, notes and relationships — for when you want a customised or private version of ATT&CK.
View on GitHub →
STIX-to-Excel
Turn ATT&CK into a spreadsheet
Part of the Python library: converts the raw data into Excel workbooks or pandas tables, so analysts can slice ATT&CK without writing any code.
View on GitHub →
TAXII 2.1 Server
Pull ATT&CK live over an API
A standard threat-intelligence API that serves the STIX data over HTTPS, so applications can fetch the latest ATT&CK on demand instead of bundling a static copy.
View on GitHub →
ATT&CK Data Model
Typed, validated ATT&CK for developers
A TypeScript library with Zod schemas that parse and validate the dataset — useful if you're building software on ATT&CK and want guarantees about the data's shape.
View on GitHub →
ATT&CK Excel Files
Ready-made spreadsheets, no setup
Human-readable workbooks generated from each release (v9 through the current v19.1), split by Enterprise, Mobile and ICS — the quickest way to simply browse the data.
attack.mitre.org →

© The MITRE Corporation. MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation, and this material is reproduced with permission. breach.co.nz is not affiliated with, or endorsed by, MITRE.

Where our data comes from

Full transparency — sources we draw from, and ones we don't

✅ Sources we draw from

OAICpenalties, determinations, NDB reports
NZ Privacy Commissionerbreach notifications, case notes
NCSC / CERT NZcyber insights, advisories
ACSCframeworks, alerts
Federal Court / courtsjudgments & orders
Have I Been Pwnednamed breach index
Company disclosures & credible mediaclearly labelled when a regulator hasn't yet acted

⛔ Sources we don't

The breached data itselfwe index the fact of a breach — never host or link leaked data
Threat-actor claims at face valueransomware gangs' "victim" posts are not proof
Anonymous forums & social postsunverified, unattributable
Public breach submissionswe don't take submissions — it keeps the register accurate & defensible
Our own estimatesif there's no official figure, we label the gap rather than guess
🔗 Every record links back to its primary source, and each field follows a fixed source rule. See the Methodology page for the full field-by-field standard.