A New Zealand payroll company’s data breach has landed on a fault line brokers are navigating more often – what a cyber policy actually covers when the insured’s own systems are clean, but a vendor’s are not.
Thankyou Payroll, which services a number of New Zealand charities, confirmed on September 10, 2026, that customer data had been accessed through a third-party reporting tool called Metabase. The company’s own systems were not compromised.
Despite that, sensitive customer information was exposed – including names, IRD numbers, email and physical addresses, bank account details, and payment histories, according to RNZ.
“We know our customers trust us with important information and we apologise for the concern and disruption this incident may cause. We understand that Thankyou Payroll is one of a number of businesses impacted as this is a global incident involving many companies worldwide,” the company said.
Read next: Half of New Zealand agencies still have an email security gap
The incident traces to a critical flaw in Metabase, a widely used open-source business intelligence platform. Metabase disclosed in August that it had identified a vulnerability allowing “an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access,” and issued a fix urging users to update “as soon as possible.”
Threat intelligence firm Dataminr noted the vulnerability exposed thousands of potential targets across sectors including government, healthcare, energy, finance, and aviation.
Thankyou Payroll said it had notified the Office of the Privacy Commissioner (OPC), required customers to reset their passwords, and strengthened its security protections. Passwords and credit card numbers were not affected.
The detail that matters for insurance brokers is not that a breach occurred – it is how. Ryan Specialty’s 2026 analysis of Dependent Business Interruption (Dependent BI) coverage puts the structural problem plainly: “Each of these events shares a common feature: the organisations that suffered operational and financial disruption were not the ones who were attacked. Their vendor was. The question for those downstream organisations is whether their own cyber insurance policy covers the loss.”
Dependent BI – also referred to as Contingent Business Interruption in some policy forms – responds when an insured suffers loss or extra expense from a disruption at a third-party vendor, where the insured’s own environment is not the point of failure.
Ryan Specialty noted that coverage triggers vary between carriers. Some policies still require a “security failure” to activate Dependent BI. A breach originating through an unpatched vulnerability in a vendor’s analytics tool may or may not satisfy that trigger, depending on how the policy defines the term. That ambiguity sits directly over the Thankyou Payroll scenario.
Vendor-related breaches are not an edge case. Third-party incidents accounted for 30% of all breaches in 2025, up from 15% the prior year, according to the Verizon 2025 Data Breach Investigations Report, which analysed more than 22,000 incidents across 139 countries.
IBM’s 2025 Cost of a Data Breach Report found that vendor and supply chain breaches cost organisations an average of US$4.91 million and took 267 days to detect and contain — the longest lifecycle of any breach vector it tracked.
Marsh’s Cyber Catalyst Report, published in December 2025 and drawing on survey data from more than 2,200 cyber risk leaders across 20 countries, found that 70% of organisations experienced at least one material third-party cyber incident in the past year.
Notification to the OPC is a legal requirement under the Privacy Act 2020. Failure to notify carries a fine of up to $10,000.
The Privacy Commissioner’s 2025 annual report recorded a 27% increase in breach notifications and a 21% rise in privacy complaints in the year ending June 30, 2025. The same report found that 67% of New Zealanders said they would likely change service providers if they heard their provider had poor privacy and security practices.
New Zealand’s Cyber Security Strategy 2026-2030, released by the Department of the Prime Minister and Cabinet in February 2026, estimated New Zealanders are losing more than $1.6 billion annually to cybercrime. In a survey of 295 large New Zealand businesses, 59% reported a cyber incident in the past year.
The Thankyou Payroll disclosure came on the same day RNZ reported a separate incident at ZenTech, a privately owned New Zealand company, in which files relating to clinical trials may have been stolen – two notable disclosures in a single news cycle.
Read next: Ransomware group claims cyberattack on Dunedin clinical trial company
New Zealand’s cyber market was classified as soft by Aon in the first quarter of 2026, with broader coverage and more competitive terms on offer.
Jack Petts, principal in Marsh Specialty’s cyber practice, has said that brokers who treat current conditions as an opportunity to sharpen policy language – rather than simply reduce premiums – are better placed when losses arise. “The first is securing strong coverage wording now,” he said, pointing specifically to contingent business interruption protection that reflects real vendor dependency.
Whether Dependent BI wording covers a loss that originates in a vendor’s unpatched platform – rather than a direct attack on the insured – turns on specific policy language. For clients in payroll, financial services, and the not-for-profit sector, that question may only get tested when a claim is already in motion.