[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3jc9gvpjf46lp":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":16,"seoTitleEn":30,"seoDescription":16,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda488252ca","media-works","MediaWorks Data Breach","mediaworks","mediaworks.co.nz","2023-03-15T00:00:00.000Z","2024-03-22T06:43:09.000Z","2026-07-03T14:51:06.409Z","2026-07-18T23:54:42.001Z","Third party breach","",[],162710,"known",null,"unknown","High",[24,25,26,27,28],"Dates of birth","Email addresses","Genders","Phone numbers","Physical addresses","\u003Cp>The MediaWorks data breach is an incident associated with the New Zealand-based media company MediaWorks, which came to public attention during the period of March 2024. The record contains 162,710 unique email addresses. The data classes include dates of birth, email addresses, gender information, phone numbers, and physical addresses. The incident is also significant because personal information from visitors who participated in online competition forms was exposed, and some individuals received monetary requests with a promise of deletion.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The risk of phishing increases when fields such as date of birth, phone number, and physical address are present along with an email address. Since media companies collect applications for contests, campaigns, and prizes, users are accustomed to receiving such messages. Attackers may reach the user with themes such as fake prizes, contest results, data deletion requests, or campaign verification.\u003C\u002Fp>\u003Cp>When fields such as name, email, phone, or address come together, attackers may approach the user as if there is a legitimate service relationship. This information alone is not proof of account takeover; however, it provides a strong starting point for fake support messages, delivery notifications, password reset attempts, and personalized fraud flows. The record does not list password or payment card data. However, date of birth and physical address can make it easier to guess the user's authentication questions or personal security answers. Messages containing requests for money should be considered as fraud in particular.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The date of the incident is recorded as March 15, 2023; the public release of the data and its addition to breach records occurred in the 2024 period. Reliable news reports indicate that MediaWorks investigated the incident and that the attackers sent payment requests to some individuals for the deletion of their data. The current data classes focus on communication and demographic fields associated with competition forms.\u003C\u002Fp>\u003Cp>There may be claims talking about millions of rows in scope; the LeakData record keeps the number of unique email addresses as 162,710. The raw number of rows is not the same as the number of unique individuals or emails. The correct communication to the user is to indicate whether a particular email address appears in this record and to provide a warning against ransom demand messages.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk may be those who have participated in MediaWorks competitions, campaigns, or online forms. Users who share their phone numbers and addresses become more vulnerable to fake prize, delivery, identity verification, or data deletion messages.\u003C\u002Fp>\u003Cp>Birth date and gender information can make messages more personal. Attackers may try to gain trust by implying that the user has entered a competition. Especially promises to delete requiring cryptocurrency or quick payment should not be considered as a reliable transaction.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matched field should check whether the same password is used in MediaWorks or related competition accounts. Even if no password is found in the record, the email can combine with a password in other violations. Messages containing money requests should not be replied to, and links should not be opened.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or application of the relevant service. The fact that the caller knows the name, email, address, or past transaction information does not prove they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, a password manager, unique passwords, two-factor authentication on applicable accounts, and the habit of removing unnecessary personal information from accounts reduce risk. Reusing the same email address across different platforms makes it easier to combine different breaches; therefore, using separate email or alias addresses for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Sharing only the required information on competition and campaign forms reduces long-term risk. Users should avoid sharing unnecessary phone numbers and addresses, use separate emails for campaign accounts, and submit data deletion requests only through official privacy channels.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check shows whether the queried email address is found in this record or not. A positive result does not necessarily mean that all data fields definitively belong to that user; however, it should be considered a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this data set and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result requires being more careful against fake messages themed around contests and campaigns. A negative result means there is no match within this record; regular checks should be maintained for other media, campaign, or contest records.\u003C\u002Fp>","MediaWorks Data Breach (162.7 Thousand Reported Records)","MediaWorks Data Breach. 162.7 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmediaworks_co_nz.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"MediaWorks","Media","New Zealand"]