Tower Probed Over Ransomware Group's Data Breach Claim
Tower Insurance is investigating a claim by a ransomware group that it has stolen data from the insurer. The group listed Tower on a cyber-extortion leak site, claiming to have accessed customer information. However, Tower says the information is unverified and is working with external cybersecurity consultants to determine the validity of the claim.
The ransomware group's listing of Tower is a tactic to pressure the company into paying before releasing any data. Even so, it is a serious signal, as general insurers hold sensitive customer data that extortion groups target. Tower has 323,000 customers in New Zealand and operates across the Pacific, making any confirmed breach potentially widespread.
New Zealand law requires organisations to notify the Office of the Privacy Commissioner and affected individuals if a breach causes or is likely to cause serious harm. Failing to notify can result in fines up to NZ$10,000. Tower is also bound by continuous disclosure obligations under the Financial Markets Conduct Act 2013 and the NZX and ASX listing rules.
The incident follows recent data breaches affecting health platforms in New Zealand. The Reserve Bank of New Zealand's General Insurance Industry Stress Test found that insurers showed resilience to claims from large cyber events but noted such events could have a significant impact on profitability.