The Biggest Data Breaches of 2025: What They Mean for NZ Businesses

2025 was the worst year on record for data breaches. US organisations alone reported 3,322 breaches, and in June researchers uncovered the single largest credential exposure in history: over 16 billion login credentials sitting in plainly accessible datasets online. The global average cost of a breach actually fell slightly to $4.44 million (down from $4.88 million), but that dip was driven by large enterprises using AI to detect and contain incidents faster, not by breaches becoming less damaging. For a New Zealand SMB without a dedicated security team, the breaches below are not distant headlines. They show the exact same gaps that exist in most local businesses right now, and every one of them was preventable with controls you should already have in place.

1. The 16 Billion Credential Exposure

In June 2025, researchers uncovered 30 exposed datasets containing more than 16 billion login credentials for services including Google, Apple, Facebook, Telegram, GitHub, and government portals. This was not a single company’s breach. It was a massive aggregation of credentials harvested by infostealer malware sitting on infected devices, combined with older breach data, left unprotected online. Almost none of it had been publicly disclosed before. It surpassed every prior breach on record, including the 2013 Yahoo breach and 2024’s National Public Data exposure.

What failed: Individual devices infected with infostealer malware, and password reuse across personal and business accounts, turned isolated infections into a global-scale credential bank for attackers.

NZ takeaway: If any of your staff reuse a personal password for a work account, or work from a personal device with no endpoint protection, your business is exposed to a breach that has nothing to do with your own network security. A security assessment will show you exactly where those gaps sit.

2. The Salesloft Drift Supply-Chain Compromise

Attackers compromised OAuth tokens belonging to the Salesloft Drift chat integration, which connects directly into Salesforce CRMs. Because the compromise sat inside a trusted, authorised integration rather than a direct attack on any single company, it gave attackers a path into the Salesforce data of hundreds of organisations at once, including major technology and cybersecurity vendors, without ever touching those companies’ own networks.

What failed: Over-permissioned API keys and OAuth tokens granted to a third-party integration, with no one monitoring what that integration could actually access.

NZ takeaway: Every app you connect to Microsoft 365, your CRM, or your accounting platform is a potential way in, regardless of how strong your own network security is. Supply-chain breaches affected 1,251 organisations in 2025, almost double 2024’s figure. Review what third-party integrations can access in your systems and switch off anything you are not actively using.

3. Qantas Airlines: Nearly 6 Million Customer Records

In June 2025, attackers exfiltrated close to 6 million customer records from Qantas by exploiting a third-party system integrated with Salesforce, exposing names, email addresses, phone numbers, and frequent-flyer details. Qantas itself was not directly breached. A vendor’s integration was.

What failed: Weak controls on a third-party contact-centre platform with a direct pipe into core customer data, and no monitoring to flag the bulk data access in progress.

NZ takeaway: This is directly relevant for any NZ business running a customer database through an outsourced call centre, booking system, or support platform. Continuous monitoring is what catches unusual bulk data access before millions of records walk out the door.

4. Yale New Haven Health: 5.5 Million Patients

A vulnerability in a third-party file transfer tool exposed the medical record numbers, treatment information, Social Security numbers, and insurance details of 5.5 million patients. 2025 was the worst year on record for large healthcare breaches, surpassing the previous record set in 2023.

What failed: An unpatched vulnerability in third-party file transfer software, one of the most common attack paths into organisations holding large volumes of sensitive personal data.

NZ takeaway: File transfer tools, backup software, and remote access utilities are prime targets precisely because they are trusted and rarely patched promptly. Ask your IT provider when these systems were last patched, not just your servers and workstations. Endpoint detection should cover these systems too, not just user devices.

5. Conduent Business Services: 25.9 Million+ Records

Conduent, a US business-process outsourcing company handling back-office data for corporate and government clients, suffered the largest named corporate breach of 2025 by victim count: more than 25.9 million records compromised.

What failed: Inadequate access controls and monitoring on systems holding sensitive data for dozens of downstream client organisations at once, turning a single provider’s weakness into a mass-exposure event.

NZ takeaway: If you outsource payroll, HR administration, or any back-office function, your data’s security is only as strong as that provider’s own controls, and you likely have no visibility into it. A tested incident response plan needs to cover what happens when the breach originates with a vendor, not just an attack on your own network.

The Pattern Behind Every Breach

Five breaches, five different causes on the surface. But the same handful of root causes keep recurring:

Root Cause Breaches Where It Was a Factor Control That Prevents It
Password reuse / infostealer malware 16 billion credential exposure Enterprise password manager, MFA on every account
Over-permissioned third-party integrations Salesloft Drift, Qantas Least-privilege API access, regular integration audits
Unpatched third-party software Yale New Haven Health Patch management covering vendor tools, not just servers
No continuous monitoring Qantas, Conduent 24/7 SOC monitoring with anomaly detection
No tested incident response plan Conduent, Yale New Haven Health Documented and rehearsed response procedures

None of these are exotic, expensive controls. They are foundational. Frameworks like SMB1001 and ISO 27001 exist specifically to ensure businesses implement them systematically rather than ad hoc.

What NZ Businesses Should Do Now

If you have read this far and recognised gaps in your own setup, here is where to start:

  1. Audit every third-party integration. List every app connected to your email, CRM, and accounting platform, and check what data each one can actually access. Remove anything you no longer use.
  2. Run a cybersecurity assessment to map your current posture against a recognised framework. You cannot fix what you have not measured.
  3. Ensure your backups are tested. Not just running, but tested. Can you restore to a known-good state within your recovery time objective? If you do not know your RTO, that is the first conversation to have.
  4. Verify your compliance posture. The Privacy Act 2020 requires notification of any breach likely to cause serious harm. Do you have a documented process for assessing harm, notifying the Commissioner, and communicating with affected individuals?
  5. Invest in your people. Human error remains a factor in the majority of breaches. Ongoing security awareness training with simulated phishing is not a nice-to-have. It is the single highest-ROI cybersecurity investment most SMBs can make.

Frequently Asked Questions

Are NZ businesses required to report data breaches?

Yes. Under the Privacy Act 2020, any organisation that experiences a privacy breach likely to cause serious harm must notify the Office of the Privacy Commissioner and affected individuals as soon as practicable. Failure to report can result in compliance notices, fines up to $10,000, and proceedings before the Human Rights Review Tribunal.

What does a data breach typically cost a small business in New Zealand?

Globally, the average cost of a data breach was $4.44 million in 2025, though that figure is pulled down by large enterprises using AI to detect and contain breaches faster. For NZ SMBs, direct costs including forensic investigation, legal fees, regulatory compliance, notification, and lost revenue typically range from $50,000 to $500,000 depending on the size of the breach and the sensitivity of the data involved.

What is the single most effective control to prevent a data breach?

Multi-factor authentication combined with least-privilege access on every third-party integration. 2025’s largest incidents, from the 16 billion credential exposure to the Salesloft Drift supply-chain compromise, were driven by weak or reused credentials and over-permissioned third-party access rather than direct attacks on hardened company networks. MFA and integration audits are baseline requirements under frameworks like SMB1001 and ISO 27001.

How often should a business run a cybersecurity assessment?

At minimum annually, with additional assessments after significant infrastructure changes, staff turnover, or security incidents. Businesses handling sensitive client data or operating in regulated sectors should conduct quarterly vulnerability scans and annual penetration tests.

What cybersecurity framework is best for NZ SMBs?

SMB1001 is purpose-built for small and medium businesses, offering tiered certification from Bronze through Diamond that scales with organisational maturity. ISO 27001 is the right choice when contractual or regulatory obligations specifically require it, but demands significantly more time and resource investment.

Do Not Wait for Your Own Breach Story

Every organisation listed above had security budgets and, in most cases, dedicated teams. They still got breached because a single third-party integration, an unpatched tool, or a reused password gave attackers a way in. The same gaps exist in thousands of NZ businesses right now. The difference between being protected and being exposed is not budget. It is discipline.

Book a free discovery call and find out exactly where your business stands, what gaps exist, and what it takes to close them before someone else finds them first.

Related reading

Let’s transform your business with our reliable IT solutions!