A cyber group says it has stolen Tower data, and the insurer is investigating with external consultants. Brokers should be ready for client questions either way
A ransomware group has named Tower Insurance on a cyber-extortion leak site, claiming to have stolen data from the dual-listed insurer. Tower says the information is unverified and is investigating.
Stuff reported on October 2 that Tower confirmed it was aware of “unverified information” posted on cyber forums relating to a potential threat. A Tower spokesperson told the publication the company had “undertaken a methodical process, working with our external cybersecurity consultants and notifying relevant authorities,” and would notify affected customers and stakeholders “immediately” if any are identified.
At the time of writing, Tower had made no announcement to the NZX or ASX.
Being named is not the same as being breached
Ransomware groups list targets publicly to pressure organisations into paying before data is released. A listing is a tactic, not a confirmation of a breach.
Even so, it is a serious signal. General insurers hold exactly the data extortion groups target: names, addresses, financial records, property details and claims histories. Tower had 323,000 customers as of January 31, 2026, according to NZX filings, and also operates across the Pacific, so any confirmed breach would extend beyond New Zealand.
What the law requires
Under the Privacy Act 2020, organisations must notify the Office of the Privacy Commissioner (OPC) and affected individuals as soon as practicable once a breach has caused, or is likely to cause, serious harm. Failing to notify carries a fine of up to NZ$10,000, a figure Consumer NZ has described as “embarrassingly low.”
New Zealand also has no express penalty for a privacy breach itself. In Australia, by contrast, serious privacy breaches can attract fines as high as AU$50 million, according to Consumer NZ, which has been pushing Parliament to close the gap.
As a dual-listed company, Tower is also bound by continuous disclosure obligations under the Financial Markets Conduct Act 2013 and the NZX and ASX listing rules. If a confirmed breach would materially affect the value of its securities, an announcement to the exchanges would be required.
Cyber risk is already here
The Tower claim follows a run of data incidents in New Zealand in recent months, including breaches affecting health platforms.
The Reserve Bank of New Zealand’s (RBNZ) 2024 General Insurance Industry Stress Test, published in May 2025, included scenarios covering a major data breach, a cloud services outage and a ransomware attack. RBNZ director of financial stability Kerry Watt said: “Cyber risks are growing and evolving quickly. This exercise helped insurers identify where they are most exposed, and where more work is needed to understand and model these risks.”
The RBNZ found insurers showed resilience to claims from large cyber events, but noted such events could have a significant impact on profitability.
What brokers can do now
Brokers with clients insured through Tower should be prepared for questions. The most useful approach is to share only what Tower has confirmed and avoid speculation, while monitoring Tower’s official statements and its NZX and ASX announcements.
Brokers should also check whether any client information they hold, or share with Tower through their own systems, could be involved. If a broker’s own systems are affected, its own privacy obligations would apply.
Keeping a simple record of when the claim became known and what clients were told is sensible practice. If Tower’s investigation confirms that customer data was accessed, brokers will be better placed to help clients through the response.
Click Here For The Original Source.
