LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › MediaWorks Data Breach (2023)

HIGH severityConfirmedHow we verify

MediaWorks Data Breach (2023): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 15, 2023

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

MediaWorks Data Breach (2023)

Reported March 15, 2023. Approximately 163K people affected.

HIGH
Severity
163K
People affected
5
Data types exposed
March 15, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The MediaWorks Data Breach (2023) (reported March 15, 2023) exposed Dates of birth, Email addresses, Genders and Phone numbers belonging to roughly 163K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the MediaWorks Data Breach (2023) breach?
163K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Data breaches involving consumer-facing media and entertainment companies have become a recurring feature of the current threat landscape. Attackers frequently target organisations that collect personal details through competitions, newsletters and online promotions, then trade or dump those records on public forums. The MediaWorks incident sits squarely in that pattern: personal information gathered from the public was later exposed at scale, with some people subsequently pressured for payment.

In March 2024, millions of rows of data linked to the New Zealand media company MediaWorks were publicly posted to a popular hacking forum. The material is reported to have affected approximately 163,000 people and included contact and identity details supplied by visitors who entered online competitions. The incident matters because the exposed fields are the building blocks of identity fraud, phishing and further extortion.

Inside the incident

Public reporting places the disclosure in March 2024, when a large volume of MediaWorks-related records appeared on a well-known hacking forum. The dataset is described as containing roughly 163,000 unique email addresses together with associated personal information collected from people who had filled out online competitions. Named data types include dates of birth, email addresses, genders, phone numbers and physical addresses; the records also contained names and the answers participants gave to competition questions.

The original reported date associated with the breach record is 15 March 2023; the public posting of the data is described as occurring in March 2024. No further technical detail about the initial intrusion method, the precise duration of unauthorised access, or the full size of any underlying database has been disclosed in the available facts. After the data appeared online, some individuals whose details were included later received ransom demands asking for payment in exchange for deletion of their information. No threat group has been publicly attributed in the facts provided.

How a breach like this happens

Incidents of this type commonly begin when an attacker obtains access to a system that stores customer or competition data—through stolen credentials, an unpatched application, a misconfigured cloud storage bucket, or a compromised third-party service. Once inside, the attacker copies large volumes of records. Those records are then either sold privately or dumped onto public forums to advertise the theft, pressure the organisation, or simply dispose of the material.

In many cases the data itself is not encrypted at rest or is protected only by weak access controls, so a single successful intrusion yields ready-to-use personal information. After a dump appears, secondary actors often scrape the files and use the contact details for phishing, smishing or direct extortion messages that claim the victim’s data will be deleted only if a ransom is paid. None of these general patterns confirms the exact pathway used against MediaWorks; they simply describe how comparable breaches typically unfold when no specific method has been disclosed.

Who is MediaWorks?

MediaWorks is a major New Zealand media company that operates radio, television and digital platforms. Like other broadcasters and entertainment groups, it routinely runs online competitions, audience promotions and registration forms that collect personal details from members of the public. Those systems typically hold names, contact information, demographic answers and sometimes additional profile data needed to administer prizes or marketing lists.

A breach at such an organisation is consequential because the data subjects are ordinary listeners, viewers and competition entrants rather than a closed employee population. The volume of records—here reported at around 163,000 unique email addresses—means a single incident can affect a sizable slice of the national audience and create lasting privacy and fraud risks for people who simply entered a contest.

What data was at risk

According to the available facts, the exposed material included dates of birth, email addresses, genders, phone numbers and physical addresses. The records also contained names and the responses participants supplied to competition questions. Approximately 163,000 unique email addresses were identified. The facts do not provide a complete inventory of every field that may have been present, nor do they confirm whether additional categories such as passwords, payment card numbers or government identifiers were included. Exact contents beyond the named types therefore remain limited to what has been publicly reported.

What's at stake

For affected individuals the combination of name, date of birth, physical address, phone number and email address is sufficient to support targeted phishing, SIM-swap attempts, account-takeover efforts and the creation of convincing fraudulent profiles. Competition answers can sometimes reveal further personal preferences or security-question material. The subsequent ransom demands reported by some victims add a direct financial and psychological pressure: people are told their data will be deleted only if they pay, yet payment offers no reliable guarantee of deletion and may simply mark them as willing targets.

For the organisation the consequences include regulatory scrutiny, loss of audience trust, the cost of investigation and notification, and the long-term reputational damage that follows when competition entrants discover their details circulating on criminal forums. Because the data originated from voluntary public promotions, the incident also raises questions about how long such information is retained and how it is protected—questions that remain open in the absence of fuller technical disclosure.

If your data was in this breach

If you entered MediaWorks competitions or otherwise supplied personal details to the company, treat the named data types as potentially exposed. Change passwords on any accounts that used the same email address, enable multi-factor authentication wherever it is offered, and be alert for unsolicited calls, texts or emails that reference your personal information or demand payment. Do not pay ransom demands; there is no assurance the data will be removed and payment can encourage further targeting. Monitor financial and credit activity for unusual behaviour and consider placing fraud alerts if you are in a jurisdiction that offers them. You can also run a free exposure scan of your email address to check whether it has appeared in known breach datasets and to receive guidance on next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyMediaWorks security record
69/100
DoxxScan™ · Moderate doxx risk
B- 75Above-average record

2 reported incidents on record.

See MediaWorks’s full breach history →
RelatedMore incidents at MediaWorks

More recent breaches

GLAMIRA Data Breach (2023)December 16, 2023Welhof Data Breach (2023)December 1, 2023Zadig & Voltaire Data Breach (2023)November 16, 2023Blooms Today Data Breach (2023)November 11, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the MediaWorks Data Breach (2023) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram