Dryden Website Cyber Security Incident

Customer Frequently Asked Questions (FAQs)

 

What has happened?

Dryden recently identified a cyber security incident involving its website environment. While there is currently no evidence that personal information was accessed, extracted,

disclosed or misused, unauthorised access to personal information cannot be conclusively ruled out.

When did Dryden become aware of the issue?

Dryden identified the incident on early August 2026 and immediately commenced an investigation and response activities.

Was my information involved?

Approximately 4,100 individuals may have been affected by the incident. If you have received a notification from us, your information may have been involved.

What information may have been involved?

Information that may have been involved includes:

  • Names
  • E-mail addresses
  • Telephone numbers
  • Residential, delivery and project addresses
  • Company or business names
  • Customer account numbers

Has my information definitely been accessed or stolen?

No. There is currently no evidence that personal information was accessed, extracted, disclosed or misused. However, unauthorised access to personal information cannot be conclusively ruled out.

Was financial information, passwords or other sensitive information involved?

No. Our investigation has not identified any involvement of:

  • Banking information
  • Payment card information
  • Passwords
  • Government-issued identity numbers
  • Health information

The information potentially involved relates primarily to contact details, business details and customer account numbers submitted through Dryden website forms.

Why am I receiving this notification if there is no evidence my information was accessed?

We are notifying individuals as a precaution because unauthorised access to personal information cannot be conclusively ruled out. We believe it is important to be transparent and provide

potentially affected individuals with information that may help them remain alert to phishing, impersonation or scam activity.

What types of customers may have been affected?

Potentially affected individuals are people whose information was submitted through Dryden website forms, including general enquiries and sample pot requests.

What has Dryden done in response?

Dryden has:

  • Investigated the incident;
  • Secured the affected website environment;
  • Implemented additional security and monitoring measures;
  • Notified the Office of the Privacy Commissioner; and
  • Notified potentially affected individuals.

Is the Dryden website safe to use?

Yes. The affected website environment has been secured and additional security measures have been implemented.

What should I do now?

We recommend remaining alert to unexpected e-mails, phone calls or text messages requesting personal information, customer account information or payment details.

If you are unsure whether a communication is genuine, please contact us using the official contact details provided below.

Could I be targeted by scams?

Because contact and business information may have been involved, we recommend remaining alert to phishing attempts, scam communications and impersonation attempts.

Be cautious of communications that:

  • Create urgency;
  • Request personal information;
  • Request payment information;
  • Request account information; or
  • Direct you to unfamiliar links or websites.

Does this incident affect my customer account?

There is currently no evidence of unauthorised activity on customer accounts arising from this incident. However, because customer account numbers may have been involved,

we recommend remaining alert to unusual account activity and contacting us if you have any concerns.

Should I stop using the Dryden website?

No. The website environment has been secured and additional security measures have been implemented.

Will I need to pay for anything?

No. Dryden will never ask you to pay a fee in relation to this incident. Be cautious of anyone claiming payment is required to protect your information or resolve the incident.

Has the Privacy Commissioner been notified?

Yes. Dryden has notified the New Zealand Office of the Privacy Commissioner.

What should I do if I receive suspicious contact?

Do not:

  • Click on links;
  • Open attachments; or
  • Provide personal information or account information

unless you are confident the communication is genuine.

If the communication appears to relate to Dryden, please contact us using the details below.

Who can I contact for more information?

Please contact: 

Phone: 0800 800 424 

E-mail: [email protected] 

Will there be further updates?

Yes. If our ongoing investigation identifies material new information relevant to affected individuals, we will provide further updates.