A ransomware group has named Tower Insurance on a cyber-extortion leak site, claiming to have stolen data from the dual-listed insurer. Tower says the information is unverified and is investigating.
In a statement to Insurance Business, a Tower spokesperson said: "We are aware that unverified information was posted on cyber forums relating to a potential cyber threat. We have undertaken a methodical process, working with our external cyber security consultants and notifying relevant authorities. We are continuing with heightened monitoring and if any customers or stakeholders are identified as impacted, they would be advised immediately."
At the time of writing, Tower had made no announcement to the NZX or ASX.
Ransomware groups list targets publicly to pressure organisations into paying before data is released. A listing is a tactic, not a confirmation of a breach.
Even so, it is a serious signal. General insurers hold exactly the data extortion groups target: names, addresses, financial records, property details and claims histories. Tower had 323,000 customers as of January 31, 2026, according to NZX filings, and also operates across the Pacific, so any confirmed breach would extend beyond New Zealand.
Read next: Privacy Commissioner splits cyber responsibility between two organisations
Under the Privacy Act 2020, organisations must notify the Office of the Privacy Commissioner (OPC) and affected individuals as soon as practicable once a breach has caused, or is likely to cause, serious harm. Failing to notify carries a fine of up to NZ$10,000, a figure Consumer NZ has described as "embarrassingly low."
New Zealand also has no express penalty for a privacy breach itself. In Australia, by contrast, serious privacy breaches can attract fines as high as AU$50 million, according to Consumer NZ, which has been pushing Parliament to close the gap.
As a dual-listed company, Tower is also bound by continuous disclosure obligations under the Financial Markets Conduct Act 2013 and the NZX and ASX listing rules. If a confirmed breach would materially affect the value of its securities, an announcement to the exchanges would be required.
The Tower claim follows a run of data incidents in New Zealand in recent months, including breaches affecting health platforms.
The Reserve Bank of New Zealand's (RBNZ) 2024 General Insurance Industry Stress Test, published in May 2025, included scenarios covering a major data breach, a cloud services outage and a ransomware attack. RBNZ director of financial stability Kerry Watt said: "Cyber risks are growing and evolving quickly. This exercise helped insurers identify where they are most exposed, and where more work is needed to understand and model these risks."
The RBNZ found insurers showed resilience to claims from large cyber events, but noted such events could have a significant impact on profitability.
Read next: Falling cyber alerts may not mean lower risk at renewal
Tower distributes mainly direct to consumers, so few brokers are likely to have significant books of Tower business. The claim is still a reminder of how attractive insurers' data is to extortion groups, and of the questions brokers should be asking about their own exposure.
Brokers hold much of the same information insurers do: client names, addresses, financial details and claims histories. Many also share it routinely with insurers and other partners through their systems. Being named on a leak site, whether or not a breach is confirmed, shows how quickly that information becomes a target. For brokers, the practical step is to review how client data is held and shared with third parties, and what their own cyber cover would respond to if a partner in that chain were compromised.
This story has been updated to include a statement from Tower.