Important messages
Important: Cyber Security incident
9 October, 2026
What happened:
On 9 September, we became aware of unauthorised access to locally stored email and data files on the main AHeadStart computer, as well as in Microsoft OneDrive, a connected laptop and a back-up drive. The data files were encrypted by the hacker, and are unable to be opened. The names of the files are still available.
Following an investigation, we have confirmed that the information was accessed by a ransomware group, who state they have successfully hacked AHeadStart Ltd, and are claiming to have stolen company data.
The incident has been reported to NZ Police, the National Cyber Security Centre, Microsoft, and the Office of the Privacy Commissioner. We are keeping in regular contact with them.
Please make sure you read about the steps you should take below, if you believe you may have been affected.
Information involved:
The information involved is different depending on a person’s involvement with AHeadStart.
It may include: names, phone numbers, email addresses, gender, date of birth, emails and attachments, tutor informationn cover sheets, progress reports, and very rarely bank account numbers.
Please note that these files were encrypted by the attacker and are unable to be opened. As we no longer have access to them, we cannot provide specific details about the information they contain.
Immediate steps you should take:
We recommend you consider taking the following steps, if you think you may have been affected:
1. Change passwords and enable MFA:
• Update your password on the email address you provided to us and any other accounts that use the same login details or recovery phone number.
• Use strong, unique passwords for important accounts, including your computer.
• Enabling multi-factor authentification where available.
2. Watch for scams:
• The NCSC recommends remaining alert for emails, messages, or phone calls that:
◦ Create a sense of urgency or pressure you to act immediately.
◦ Ask you to click links, open attachments, or download files unexpectedly.
◦ Request passwords, verification codes, or sensitive personal information.
◦ Appear to come from a trusted organisation but contain unusual wording, requests, or sender addresses.
◦ Reference information about you to attempt to gain your trust.
• You should remember:
◦ do not provide passwords or full financial details by phone/email
◦ do not click links in unexpected messages
3. File a Police report:
• A Police report has been filed for the attack. If you notice signs of identity misuse (e.g., unexpected mail, calls about accounts you didn't open), file a report with NZ Police online or on 105.
4. IDCARE and Office of the Privacy Commissioner:
• You can also contact IDCARE (0800 201 415) for expert guidance and support or the Office of the Privacy Commissioner (0800 803 909) to make a complaint.
Next steps:
We have already taken several steps to strengthen our security protocols to prevent future incidents. We will also be revising the information we collect, to make sure it is fit for purpose.
We sincerely apologise to everyone affected. I understand that you trusted AHeadStart with your information, and I recognise the concern and frustration that this incident may cause.
If you have any questions, please don’t hesitate to get in touch.
Sincerely,
Melanie
Melanie Coker
Managing Director
AHeadStart Ltd
021 156 9281
[email protected]