Christchurch City Council – Data breach response

Data breach update 14 November 2022

On 24 August, Christchurch City Council was made aware that a third-party had illegally accessed the He Puna Taimoana cloud server and that certain customer information stored on that server had been downloaded by the third party.

On that same day, we engaged our third-party vendor who administers the He Puna Taimoana cloud server. They were able to install a security update and confirm that the exploited vulnerability was resolved.

We have since been liaising directly with customers whose data may have been illegally accessed as a result of the breach. In response to specific customer questions and where requested, we have provided confirmation of the specific customer information which may have been exposed.

We decided to retain our then-existing records of collected proof of residency information for a short period following the breach to enable us to appropriately respond to individual queries regarding the specific proof of residency information that may have been impacted and to support our investigations into the breach.

We’ve now set a date of Friday 25 November 2022 to securely and permanently delete all proof of address information collected from He Puna Taimoana customers and which is currently stored on He Puna Taimoana's cloud server. From this date we will no longer be able to respond to He Puna Taimoana customer requests about what proof of address information they had supplied. 

Please get in touch before this date if you want to make a request. You can contact us by email at info@hepunataimoana.co.nz, by phone on +64 3 941 8999 or 0800 800 169.

As a result of the breach we carried out an internal review He Puna Taimoana's personal information collection practices. As a result of this review we have implemented new processes in respect of the collection, processing and storage of proof of address information from He Puna Taimoana customers. Our priority is to ensure that our data management practices not only meet our obligations under the Privacy Act 2020 but align with best practice.

Proof of address evidence collected by He Puna Taimoana for the purposes of verifying resident discounts will now be limited to rates bills, Christchurch City Libraries membership cards and other utilities bills.

We would like to offer our sincere apologies to our valued He Puna Taimoana customers for any inconvenience this incident may have caused. As an organisation, we take the protection of data and cyber security very seriously and we’re continuously looking at improvements in our customer identity and security practices.

This Q&A information is current as of 7 September 2022.

The breach

What happened?

On Wednesday 24 August, we were made aware that a third-party had illegally accessed the He Puna Taimoana cloud server and that certain information stored on that server has been downloaded by the third party.

At this stage, we understand that the third-party who accessed the He Puna Taimoana is an individual 'white hat hacker' who exploits computer systems or networks to identify vulnerabilities in order to encourage improvement or enhancement to the security of those systems or networks. The third-party actor has claimed that approximately 20,000 files were exposed on the He Puna Taimoana cloud server. Our third-party vendor, who administers the He Puna Taimoana cloud server, has been able to verify that a single bulk data download from the He Puna Taimoana server had taken place in the last 90 days.

Information affected

What information was accessed?

At this stage our investigations are still ongoing, however, we understand that the information accessed and downloaded by the third-party actor from the He Puna Taimoana cloud server consists of scanned copies of proof of residency information used by He Puna Taimoana to verify address information for the purpose of offering resident discounts (Affected Information).

The Affected Information comprises a range of scanned materials such as copies of drivers' licences, rates invoices, tenancy agreements, utility bills, other Council membership cards and in limited instances passport copies. This information contains personal information, predominately names and addresses of He Puna Taimoana customers and potentially other sensitive categories of personal information including passport and drivers' licence details.

How many He Puna Taimoana customers may be affected?

At this stage, we have reason to believe that up to 20,000 files stored on the He Puna Taimoana cloud server may have been illegally accessed and downloaded by the third-party actor.

We presently have no reason to believe the information has been further disclosed by the third-party actor other than to the third party who has informed us of the breach.

What can I do to protect myself?

While at this stage we have reason to believe that the affected files are unlikely to be used by the third-party actor for further malicious purposes, we cannot be certain of that fact.

We recommend that you remain vigilant to further potential malicious use of your personal information. Some ways you may choose to mitigate or avoid further potential harm include:

• remaining alert to potential malicious emails or texts which use your personal information. Netsafe has published some helpful guidance on how to stay safe online and how to avoid scams. See Netsafe's guidance on how to avoid scams here netsafe.org.nz;

• if you suspect you’ve received a malicious email or text, do not click any links. Delete the message and report it to your email or telecommunications provider;

• if you have provided He Puna Taimoana with a copy of your passport or driver's licence as evidence of proof of residency, then for piece of mind you may choose to have that form of identification replaced; and

• while financial details used for purchases such as credit card and other payment card details have not been compromised (He Puna Taimoana does not collect and store this information), you may choose to contact your bank to inform them that your personal information may have been accessed and your bank can advise you on any additional steps which may be prudent to take to ensure the security of your accounts.

Our response

How has Council responded to this?

This incident has our full attention. Our immediate priority has been to secure the underlying vulnerability in our systems which facilitated the breach.

On becoming aware of the breach, we immediately engaged our third-party vendor who administers the He Puna Taimoana cloud server. The vendor was able to install a security update and has since confirmed that the vulnerability which was exploited has now been resolved.

Our priorities are now:

• working alongside the Office of the Privacy Commissioner (OPC), to engage further with the third-party actor to ensure the downloaded files are deleted securely;

• to further investigate exactly what happened. We will make whatever changes are needed to ensure our systems remain secure and our data collection and management processes are in line with best practice; and

• provide information and updates regarding the breach to affected individuals as quickly as possible.

Who has been notified?

We have formally notified the OPC in respect of the breach and are continuing to work with them as part of our broader response. We are conscious of our obligations under the Privacy Act 2020 and how this incident could impact He Puna Taimoana's customers and our broader stakeholders.

We have also notified those individuals whose personal information may have been interfered with in connection with the breach. We will continue to update the Q&A information regularly on this page.

Has this impacted He Puna Taimoana's ability to operate?

The vulnerability exploited in respect of this breach has now been secured. He Puna Taimoana's core functions are now secure and He Puna Taimoana's facilities remain open for business.

What measures have you put in place to make sure this doesn’t happen again?

We have launched an internal investigation into how this breach occurred and what steps we can take to ensure it doesn’t happen again.

We will continue to engage with the OPC and the relevant third-party vendors involved in respect of the breach throughout our further investigations to review our existing systems and processes. Our priority is to ensure our data management practices not only meet our obligations under the Privacy Act 2020 but align with best practice.

Your rights

Do He Puna Taimoana customers have to notify the Office of the Privacy Commissioner?

We have already notified the OPC of the breach and are working with them as part of our response. We are conscious of our obligations under the Privacy Act 2020 and how this incident could impact He Puna Taimoana's customers and our broader stakeholders.

What should you do if you are not satisfied with our response?

We thank you for your support and patience and we carry out our further investigations in the breach.

If you have questions or require any further information in respect of the breach, we encourage you to contact us:

• by email at info@ccc.govt.nz; or

• by phone on +64 3 941 8999.

If you are not satisfied with our response, you have the right to complain to the Office of the Privacy Commissioner. Please phone 0800 803 909 (Monday to Friday, 10am to 3pm), access its website at www.privacy.org.nz, or mail to PO Box 10094, Wellington 6143.

#hepunataimoana

Share your experience