Security Notice – September 2026
Last updated: 4 September 2026
KOKIO recently identified unauthorised access to a system that we used to manage customer relationships and invoicing.
We identified the incident on 3 September 2026. Our investigation indicates that unauthorised access to the affected system began on or around 19 August 2026.
What happened?
An unauthorised party exploited a vulnerability in software used by our customer relationship management system and gained unauthorised access through that application to the hosting account used by the system.
As soon as we identified the incident, we began an investigation and took steps to contain and secure the affected environment.
The compromised application has been removed and rebuilt using clean, updated software. Malicious files and processes identified during our investigation were removed, relevant credentials were changed, existing sessions and customer portal credentials were invalidated, and customer access to the affected system was disabled.
Our hosting provider has also reviewed the environment and has confirmed that its malware checks and review of the hosting account are currently clear.
What information may have been affected?
The affected system contained information used by KOKIO for customer administration and invoicing.
Depending on your relationship with KOKIO, this may have included:
- Your name and email address;
- Customer and account information;
- Invoices and invoice amounts;
- Records of payments or receipts; and
- For some customers who previously used our online customer portal, a hashed portal password.
Customer portal passwords were not stored in plain text.
The affected system was not used to store customer banking credentials or payment-card details.
Was customer information stolen?
At present, we have not identified evidence confirming that customer information was downloaded or subsequently misused.
However, because unauthorised access to the system occurred, we cannot rule out the possibility that information stored in the system may have been accessed.
We are therefore notifying customers as a precaution and in the interests of transparency.
What have we done?
We have taken a number of measures in response to the incident, including:
- Securing and rebuilding the affected system;
- Removing identified malicious files and processes;
- Changing relevant credentials;
- Invalidating existing application sessions and customer portal credentials;
- Disabling customer access to the affected system;
- Introducing additional authentication controls; and
- Conducting additional checks with our hosting provider.
The affected CRM platform is also being retired, with relevant business records being migrated to a new environment.
Our technical investigation is substantially complete. We will continue to monitor the situation and will provide further information if any material new findings come to light.
What should I do?
We recommend being cautious about unexpected emails, messages or requests that appear to come from KOKIO, particularly messages requesting passwords, payments or personal information.
If you previously used the KOKIO customer portal:
- If you used the same or a similar password on another website or service, we recommend changing that password on those other services as a precaution.
- Be cautious of unexpected messages referring to KOKIO invoices, payments, account information or password requests.
We have not identified evidence that customer portal passwords have been recovered from their stored hashes or used fraudulently.
Contact us
If you have any questions about this incident or believe you may have been affected, please contact:
We apologise for any concern this incident may cause. We take the security and privacy of our customers' information seriously and will provide further information if any material new findings are identified.
