Marcus
banner
utf9k.net
Marcus
@utf9k.net
Platform Engineer by day, side projects by night

https://utf9k.net
Hmm, I wonder if the ransom has been paid.

I overlooked it given all the new articles about Kazu that popped up this morning but they had taken down the various posts about MMH in their channel as well as the Tor ransom page.
January 7, 2026 at 9:03 AM
Reposted by Marcus
As of 21:25 (so 5 minutes before 9:30pm) that "banner" seems to entirely replace the login page, there's no option to log in. So perhaps they started early.
January 7, 2026 at 8:27 AM
ManageMyHealth have just put a banner up on their sign-in page stating that they will be performing scheduled maintenance at 9:30pm - 10:00pm and that their systems will be unavailable during that period.

app.managemyhealth.co.nz/authenticati...
Manage My Health Patient Portal
ManageMyHealth™ is a secure health portal that provides 24/7 access to your health records, video consultations, hospital letters, referrals, appointment bookings, repeat prescriptions, and direct mes...
app.managemyhealth.co.nz
January 7, 2026 at 8:20 AM
Reposted by Marcus
New Zealand’s privacy watchdog and Manage My Health were both warned of security issues with the Manage My Health platform six months before hackers would hold patients' private health data as ransom.
Manage My Health, Privacy Commissioner warned of security risks six months ago
ebx.sh
January 7, 2026 at 5:46 AM
If you recall the 2024 OIA that was asking for audit findings from Te Whatu Ora on ManageMyHealth, Te Whatu Ora said they were aware of MoH having done reviews but didn't have access.

I filed an OIA with MoH who just said they're transferring it back to Te Whatu Ora 🤦

fyi.org.nz/request/3340...
GP Security Reviews - a Official Information Act request to Ministry of Health
Back in April 2024, an OIA was submitted to the Office of Dr Shane Reti querying about any "audit findings, documents, and emails pertaining to the security of Medtech and ManageMyHealth". This reque...
fyi.org.nz
January 7, 2026 at 5:41 AM
managemyhealth.co.nz/mmh-cyber-br...

MMH state police advice is to not interact with hackers, they will behind notifying patients in the next 24 hours via email, they are establishing an advisory board and their mobile app will instead redirect to their web app temporarily.
MMH Cyber Breach Update 7 January 2026 | Manage My Health
Further to our 6 January 2026 statement regarding the cybersecurity incident, Manage My Health provides the following update.
managemyhealth.co.nz
January 7, 2026 at 4:55 AM
Oh, I didn't see this until just now but I am honoured to have been personally served a copy of the injunction.

They said they "refer to my blog post" but it isn't explicitly clear to me if they are implying that "information obtained from it" means they would like me to remove or redact it?
January 7, 2026 at 4:53 AM
Reposted by Marcus
That’s one of the hardest parts of PCI compliance, keeping credit card details out of places they should never be in the first place.
January 7, 2026 at 3:58 AM
As a small anecdote, sometimes customers can also be just as bad.

At a previous company I worked at, our customers (businesses) would keep putting their customers (citizens) credit card numbers in an unencrypted notes field.

That product team tried blocking CC formats, putting a banner, all sorts
January 7, 2026 at 3:49 AM
It's unclear whether they are referring to MMH, Saudi Icon, a new unrelated breach or a combination of these three.

I have been touching grass for a couple hours so I'm just catching up now
January 7, 2026 at 3:05 AM
Here's the Neighbourly judgment

cdn.utf9k.net/documents/00...

I haven't been following the story myself so I'm not sure if the stats are new: 213 million lines of data totalling 150GB (according to the seller's listing)

No real technical insight at all
cdn.utf9k.net
January 6, 2026 at 11:35 PM
Something I forgot to mention is that until now, the presence of lab results etc in the samples seemed to contradict only Health Documents being targeted, given there are dedicated tabs in-app for lab results etc

This article removed that contradiction in my mind and explains how both can be true
Some very good stuff in there, like even the origin of Kazu's avatar

I'll surface this one part as it's important but only a claim.

> Kazu also claimed they would delete records belonging to minors and elderly patients regardless of whether a ransom was paid.

www.nzherald.co.nz/nz/hacker-cl...
'I do it for the money': Hacker claims to be behind health data breach
'Don’t worry, this will be over soon,' the person identifying as the hacker Kazu said.
www.nzherald.co.nz
January 6, 2026 at 11:07 PM
Not to be forgotten, I've also asked the Auckland High Court for a copy of the Neighbourly judgment so maybe we'll get some technical details too.

I'll share a copy (if the publishers notes allow) once I get it.

I guess DocumentCloud is what you're meant to use but I don't use MuckRock 😄
January 6, 2026 at 10:47 PM
Reposted by Marcus
THIS.
The next phishing campaign will be fake breach notifications that ask you to log in to view the notifications.
January 6, 2026 at 9:47 PM
Kazu seems to have taken down the message in their Telegram channel claiming that they were in Cuba.

They also scrubbed the contents of the original forum post advertising the MMH data for sale, about 30 minutes ago.

Perhaps they are getting annoyed at all the incoming media questions
January 6, 2026 at 9:55 PM
Reposted by Marcus
🤣

If we're talking biz this is terrible ROI for a lot of work, though I guess it's not like they burned any valuable oday for it, so... ¯\_(ツ)_/¯
January 6, 2026 at 9:21 PM
Yesterday just ended up being even more eventful than all of the previous days 🤦‍♂️

That said, it seems like all of the major news outlets are in direct contact with Kazu (a few I gave directions on how) so hopefully I have now put myself out of a job
Anywho, I'm off to work now and with The Post catching news before I did, it's probably time for me to retire my temporary journalism hat and to return to being a regular, boring citizen.

Thanks for everyone who took an interest in my updates!
January 6, 2026 at 9:18 PM
Some very good stuff in there, like even the origin of Kazu's avatar

I'll surface this one part as it's important but only a claim.

> Kazu also claimed they would delete records belonging to minors and elderly patients regardless of whether a ransom was paid.

www.nzherald.co.nz/nz/hacker-cl...
'I do it for the money': Hacker claims to be behind health data breach
'Don’t worry, this will be over soon,' the person identifying as the hacker Kazu said.
www.nzherald.co.nz
January 6, 2026 at 8:35 PM
I haven't done any close analysis of every timestamp but thinking back to when I've seen them active, I think that could plausible.

They tend to stop responding around 4pm (10pm CST) and I've seen them online as early as midnight (6am CST)
I'm not entirely sure.

Earlier today, they quote an excerpt from Simeon Brown about forensics working to narrow down the country in their Telegram with a caption that they're in Cuba.

No way to verify that but they did also express their reaction to the investigation with a popcorn eating sticker
January 6, 2026 at 11:30 AM
Yesterday, I had emailed the NCSC to report that Kazu mentioned IPFS would be the distribution mechanism of choice if the breach is distributed.

I had also asked, in the event that I learn anything useful, where can I send it because their reporting forms are not geared towards generic tips
January 6, 2026 at 9:43 AM
It just occurred to me that they only referenced the first sample and it appeared that they may still not know about the accidentally-included-in-a-different-breach second sample which is the one that contained the two passports
> By way of example the documents include highly sensitive and confidential descriptions of patients’ ailments, injuries, health conditions, investigations, procedures,
and diagnoses; personal information, such as patient contact details, dates of birth and addresses; and (cont...)
January 6, 2026 at 7:42 AM
Reposted by Marcus
> The stolen data relates to [...] approximately 45 Northland-based GP practices, approximately 355 “referral-originating” GP practices across a number of regions and patient-uploaded files. This is a subset of the stolen data and is
not limited to Northland patients.
January 6, 2026 at 6:54 AM
Here's a copy of the High Court injunction decision released to me by the Wellington High Court. The attached publishers notes state that there are no restrictions on publications.

Change the URL to 2+PS.pdf for the publishers notes if you're interested

cdn.utf9k.net/documents/Ma...
cdn.utf9k.net
January 6, 2026 at 6:43 AM
@mk-moodkiller.bsky.social Miku Expo last year was very good
January 6, 2026 at 5:54 AM
Oh hey, I recognise that screenshot 😄

The giveaway is that pixellation done via @cleanshot.bsky.social and watching it float around is quite fun

Obviously, if it was art or an original creation, I'd be disappointed

I was quite surprised how far they zoomed in so good thing I used a retina display
January 6, 2026 at 5:27 AM