Thousands of New Zealanders may have been affected by a major data breachthat occurred at Nitro PDFrecently. The breach has exposed email and passwords.

On Friday afternoon, cybersecurity services provider Cert NZ said the Australian-based online document creation and sharing app had suffered a "significant" data breach
According to the information, an unauthorized user claimed to have gained access to 2.6 million email addresses and encrypted passwords, including more than 4,000 “.nz” email addresses. In fact, as he himself stated, he has published this information online.
“Cert NZ understands that further data has been released in this breach, details are yet to be confirmed,” the cybersecurity firm said in a statement . “The authenticity of the data could not be verified.”
Given that some of the New Zealand users have email accounts ending in “.com,” many others could have been affected, a Cert NZ spokesperson said.

The agency is trying to contact all users affected by the breach to help them mitigate any security risks from the incident.
Nitro PDF is reportedly used by more than 10,000 customers, including tech giants Google, Apple , and Microsoft.
Cert NZ recommends that anyone using the Nitro PDF service immediately change their password to a stronger one, containing more characters, such as a combination of letters, numbers and symbols, which will be harder to guess. They should also inform others of the accounts on which they use the same password. It is recommended that users choose different passwords for each of their accounts and use a good password manager to make it easier for them to remember them.
