A cybercrime group is claiming it has breached Tower Insurance. Tower is contesting it. Either way, your clients will have questions, and you need answers ready
A ransomware group has named Tower Insurance on a cyber-extortion leak site, claiming to have stolen data from the dual-listed insurer. Tower is pushing back on the claim, but brokers should not wait for a verdict before taking action.
Stuff reported on October 2 that Tower confirmed it was aware of “unverified information” posted on cyber forums relating to a potential threat. A Tower spokesperson told the publication the company had “undertaken a methodical process, working with our external cybersecurity consultants and notifying relevant authorities,” and would notify affected customers and stakeholders “immediately” if any are identified.
At the time of writing, Tower had made no announcement to the NZX or ASX.
Being named is not the same as being breached
Ransomware groups list targets publicly to pressure organisations into paying before data is released. It is a tactic, not a confirmation. That distinction matters when assessing immediate client risk – but it offers limited comfort.
Once data circulates on the dark web, it does so regardless of whether a ransom is paid or a breach is formally confirmed. The question for brokers is not what the criminals are claiming. It is what exposure your clients may have if the worst turns out to be true.
Tower’s customer base stood at 323,000 as of January 31, 2026, per NZX filings. General insurers hold exactly the data extortion groups target: names, addresses, financial records, property details, and claims histories. Tower also operates across the Pacific, so any confirmed breach would extend beyond New Zealand.
Read next: Privacy Commissioner splits cyber responsibility between two organisations
What the law says – and what it doesn’t
New Zealand’s privacy framework offers limited deterrence for companies that fail to protect customer data. According to Consumer NZ, in Australia, serious privacy breaches can attract fines as high as AU$50 million. In New Zealand, there is no express penalty for a privacy breach itself – a gap advocates have been pushing Parliament to close for years.
Under the Privacy Act 2020, organisations must notify the Office of the Privacy Commissioner (OPC) and affected individuals as soon as practicable once a breach has caused, or is likely to cause, serious harm. Failing to notify carries a fine of up to NZ$10,000, a figure Consumer NZ has described as “embarrassingly low.”
On top of that, changes are now in force. The Privacy Amendment Act 2025 introduced a new requirement obliging organisations to notify individuals when their personal information is collected indirectly. Those changes came into force on May 1, 2026, according to the New Zealand Ministry of Justice.
As a dual-listed company, Tower is also bound by continuous disclosure obligations under the Financial Markets Conduct Act 2013. If a confirmed breach would materially affect the value of Tower’s securities, an immediate NZX announcement would be required. Watch the exchange feed.
Cyber risk is not a future problem
New Zealand’s run of data incidents in recent months – healthcare breaches, medication platforms taken offline, unauthorised access to health platforms – confirms that cyber risk is no longer a hypothetical.
The Reserve Bank of New Zealand’s (RBNZ) 2024 General Insurance Industry Stress Test, published in May 2025, included scenarios covering a major data breach, a cloud services outage, and a ransomware attack. RBNZ director of financial stability Kerry Watt said: “Cyber risks are growing and evolving quickly. This exercise helped insurers identify where they are most exposed, and where more work is needed to understand and model these risks.”
The RBNZ found insurers showed resilience to claims from large cyber events, but noted such events could have a significant impact on profitability.
Read next: Falling cyber alerts may not mean lower risk at renewal
What to do now
Pull your Tower client list. Document when you became aware of this claim and what you did in response.
New Zealand’s low penalty environment means organisations face less pressure to self-report quickly than their Australian counterparts. That makes the quality of an insurer’s breach response more important here – and how brokers respond to that response becomes a professional liability issue, not just a reputational one.
If Tower’s investigation confirms client data was accessed, the question will not be what happened at Tower. It will be what you knew, when you knew it, and what you did next. Start building that record now.
