Squirrel breach exposed ID documents of up to 600 New Zealand investors
- Organization
- Squirrel
- Exploit
- Hacking
- Industry
- Financial Services
The incident became public on July 25, 2024, when Squirrel, a New Zealand mortgage broking and peer to peer lending firm, said an unauthorised party had reached a third party system used in its investor registration process and extracted identity details belonging to up to 600 people.
The exposed records covered investors who had registered in the weeks before the breach was found. RNZ reported the window as the 30 days to July 21, while the New Zealand Herald put it at June 20 to July 20. The data included names, dates of birth, and passport or driver licence numbers. Squirrel said no usernames, passwords or bank account details were taken, and that images of the documents themselves were not compromised.
The system involved was used for anti money laundering and know your customer verification, and it retained identification details for 30 days so records could be corrected if they had been captured incorrectly. Chief operating officer Dave Tyrer said responsibility lay with Squirrel rather than with the provider, and that the firm was 99.9 percent certain the attacker was based overseas. No ransom demand or other contact from the attacker was received.
Squirrel said it closed the weakness, notified the Privacy Commissioner, contacted affected investors and offered to reimburse the cost of replacing identity documents. It also opened a support line for people with questions.