New Zealand, 6 January 2026 – Hackers have demanded a ransom worth US $60,000 (about KSh 7.7 million) from Manage My Health, New Zealand’s largest online patient portal, after gaining unauthorised access to sensitive medical records, sparking urgent reviews by authorities and fears of identity theft among tens of thousands of patients.
The cyberattack, first identified on 30 December 2025, compromised the Health Documents module of the platform, which is used by general practices across the country to manage patient records.
Manage My Health estimates that 6 – 7 per cent of its roughly 1.8 million registered users, about 108,000 to 126,000 people, may have had personal information accessed by the hackers.
Hackers operating under the name “Kazu” warned via the messaging app Telegram that they would release more than 400,000 stolen files if the ransom was not paid within 48 hours.
The deadline arrived early Monday, but so far no additional data has been publicly leaked.
“We know exactly how valuable health data is and how sensitive it can be,” the group wrote in a Telegram post, adding that they are motivated by profit and reputation rather than political goals.
The stolen documents reportedly include medical records, diagnostic results, prescription information, personal contact details and other highly sensitive material, making it potentially more damaging to individuals than typical financial data breaches.
Cybersecurity experts note that health records are often worth 10–50 times more than credit card data on the dark web because they contain identifiers that can fuel identity fraud or extortion.
Government Rejects Paying Ransom
New Zealand Health Minister Simeon Brown has been clear that the government’s position remains that ransom should not be paid.
Brown described the incident as “pretty unacceptable” and ordered an urgent review into the breach, including how it occurred and how data systems can be strengthened.
Authorities are also investigating whether the ransom deadline has been extended and how patients will be notified as part of the Privacy Act process.
Manage My Health said communications about the ransom are a matter for police while the investigation continues.
Urgent Clinical and Patient Concerns
The fallout from the breach has led to concern among general practitioners (GPs), who are being inundated with questions from patients unsure if their details were accessed.