Our sourcing standard, in full. This page is ad-free by design — trust pages carry no advertising.
breach.co.nz is an index of public record. We report data breaches that regulators, courts or the affected organisations have already made public. We make no original allegations, take no public breach submissions, and never host or link to breached data itself.
New Zealand and Australia, from 2018. We cover "official + major-news" breaches — anything with regulator or court action, plus significant, credibly-reported incidents. Note: a headline using the word "breach" is not always a data breach — physical-security and service-availability incidents are out of scope.
Tier A — Confirmed: sourced from a regulator (OAIC, NZ Privacy Commissioner, NCSC) or a court. Published as fact.
Tier B — Reported: credible media or company disclosure before regulator action, labelled "Reported — awaiting official confirmation." We publish a Tier-B record only once the affected organisation has publicly admitted the breach and it is in the hands of an authority (regulator, Police or court), with at least one credible independent source. Threat-actor claims and leak-site posts do not qualify.
We never assert a figure we don't have a source for — we label the gap instead of estimating it. Each data point is graded: Confirmed (regulator/court), Company-confirmed (the organisation's own disclosure), or Media-reported (press). When a regulator later acts on a Tier-B case, it is upgraded to Tier A and the official source added.
Every record carries a correction and right-of-reply path. If you believe a record is inaccurate or out of date, contact us. We investigate the claim against the underlying sources and then either correct the record or notify you of our decision to leave it as it stands — we do not amend or remove records on request alone: breach@govern.co.nz.