Cybersecurity incident at Taupō District Council
12 noon Thursday 23 October
Taupō District Council has today experienced a cybersecurity incident involving a phishing email sent from a council email address.
While we're working hard to investigate and understand this incident we're telling the community to ignore and delete any emails or messages that ask you to update bank account details – either yours or ours. We haven’t changed our bank account.
Some people may have received a phishing email, which may appear with subject lines such as “(person’s name) shared ‘PO 382738.docx’ with you” or “(person’s name) shared a page with you”, which have the potential to compromise recipients’ security.
If you have not opened the email or clicked on any links, you may safely delete it.
If you did open the email and entered your credentials or any sensitive information, we strongly recommend that you:
- Change your passwords immediately, especially for any accounts that may use the same credentials.
- Notify your IT or network security team so they can take appropriate precautions.
- Monitor your accounts for any unusual activity.
Taupō District Council is treating this incident with the utmost seriousness. Our IT and crisis management teams are actively investigating the breach and working to identify and mitigate any further impact.
If you receive an email from a Taupō District Council staff member and are unsure of its legitimacy, please contact us directly on 07 376 0899 to verify.
We appreciate your understanding and cooperation as we work to resolve this matter.