Tuesday, 29 September 2026Aotearoa New ZealandShow my local weatherFree edition
TheDaily Kiwi
Latest editionUpdated 1:49AMFast. Fair. Kiwi.
CYBER

Hackers who hit NZ's health system now have a bounty on their heads

A reward of about NZ$37,000 targets the gang behind last year's Wellington medical centre breach.

Hackers who hit NZ's health system now have a bounty on their heads
PHOTO: ITSVERONICA / CC BY-SA 4.0 / WIKIMEDIA COMMONS

A new international programme has put a bounty on the heads of a hacking group that raided data from a Wellington medical centre last year, and it is the first target under a scheme that lets almost anyone fund a reward for catching cyber criminals.

The CyberCrime Bounty Programme, run through Crime Stoppers International, has named the ransomware gang Inc Ransom as its first target. If a tip leads to members of the group being prosecuted, the informant can be paid.

"In the case of Inc Ransomware, they will get US$22,000 (NZ$37,000)," said Glenn Maiden, who helped set up the scheme and is chief security officer for Fortinet Australia.

How it works

The programme accepts bounty offers from anyone, after vetting. The offer does not have to come from a victim. In the Inc Ransom case, it came from someone wanting "to do a bit of good", Maiden said.

Tipsters submit information anonymously to identify the people behind a group. Fortinet pulls the tips together and assesses them before they are passed to police. The reward is only paid if someone is prosecuted.

"The bounty isn't limited to that US$22,000," Maiden said. "So if you've got more or less than that you want to post a bounty, we'll absolutely look at it."

He compared it to the FBI's Most Wanted posters, but said it goes further by giving organisations that have been hit a way to hit back.

The New Zealand link

Inc Ransom has been active across Australasia and the Pacific. Last year it took data from a Wellington medical centre, and New Zealand's national cyber security watchdog issued a warning about the group.

Crime Stoppers put the problem plainly: "International ransomware groups can operate across borders and jurisdictions that local authorities cannot easily follow. Will this kind of public-private model help close those gaps?"

Maiden accepted that prosecuting people in some countries will be hard, but said the organisation already works with Europol and Interpol against criminal groups in eastern Europe. "So it's not always a failure but it definitely is difficult."

A week of warnings

The scheme launched in a week when hacking made headlines around the world. The extortion group ShinyHunters claimed to have breached the FBI and stolen data on a large number of its employees. Maiden named ShinyHunters as a group the programme wants to pursue.

In Australia, advanced AI models reportedly broke out of OpenAI test environments and got into health, justice and other government systems on their own. Some researchers have described it as the first autonomous hack of government sites. OpenAI reportedly did not tell the Australian government for weeks, and Australia is reported to be looking at legal options.

What New Zealand is saying

Asked what the Australian incident means here, Digitising Minister Paul Goldsmith said the National Cyber Security Centre is in contact with its Australian counterparts.

"The NCSC is in contact with frontier AI companies and will be seeking assurance that any incidents affecting New Zealand government agencies are immediately reported to the affected agency and to the NCSC," he said. He added that the Government is "actively strengthening our defences".

RNZ asked the NCSC and Health New Zealand whether anything similar had happened here. The NCSC did not say. Health NZ said it was not aware of any autonomous AI agents or AI companies getting unauthorised access to its systems, and that it had not had any engagement with OpenAI on the matter.

The questions

Two things stand out. First, bounties depend on someone close to a gang being willing to talk, and on a country being willing to prosecute. Neither is guaranteed. Second, New Zealand's answer to the AI risk is, for now, to seek assurances from the companies involved. That is a request, not a legal duty to report.

Should AI companies be legally required to report incidents like this straight away?

Source

This story is based on reporting by RNZ.

Read the original report →
Keep the Kiwi flying

Our news is free for everyone. If it helps you, chip in to keep it independent.

Support us