A “cyber incident” became a confirmed privacy breach this week. Dunedin clinical trial company Zenith Technology (ZenTech) has confirmed personal information was compromised in a cyberattack, including health and identifying data collected during clinical trials. The admission arrived not in a press conference but in a public notice buried in Friday’s Otago Daily Times, a week after police began investigating.
ZenTech’s own words were blunt: it understood “some of this information is likely to include health-related and identifying data collected as part of the clinical trial process.” That is a long way from the vague “potential impact” language companies usually hide behind.
A theft model that defeats your backups
The breach first surfaced publicly around 10 September, when files attributed to ZenTech turned up online and Health Minister Simeon Brown was briefed. The ZaWoo ransomware group claimed responsibility, posting sample data purporting to show a patient record with a name, NHI number, address, date of birth, referring doctor and blood test results, then demanding bitcoin under threat of publication.
The technical detail matters for every business leader. Threat intelligence analysis found an internal server was compromised and 67GB of data exfiltrated, with no evidence any of it was encrypted. That points to pure data theft, not traditional ransomware. It is a model that defeats the single most common defence: robust backups. If your files are stolen rather than locked, restoring from backup does nothing to stop them being published. The leverage sits entirely in the threat of exposure.
Health data makes the target doubly attractive. Dr Abhinav Chopra, a cybersecurity expert at the University of Auckland, explained why it commands a premium: “They have information about their bodies and their allergies, they’ve got clinical information, which is information that cannot be changed, so the dataset is quite static and can be used by a number of buyers on the black market.” Unlike a password, a diagnosis cannot be reset.
The liability trap most coverage is missing
Here is the part that should have legal and IT teams talking this week. ZenTech is a contractor. It processes data on behalf of pharmaceutical companies, Health NZ and other health sector principals. Under the Privacy Act 2020, those principals remain legally responsible for how their contractors handle data. A breach at ZenTech is not just ZenTech’s problem.
Adelphi Insurance Brokers’ 2026 cyber market review flags three exposure points for health-adjacent organisations. First, principal liability under the Privacy Act. Second, the 72-hour notification clock, which starts when the contractor becomes aware of a breach, not when the client is told. If ZenTech took days to notify Health NZ, Health NZ’s own obligations were already running down. Third, underwriting misclassification, where contract research organisations holding sensitive health data are not always assessed with a risk profile that matches their true exposure, leaving coverage short of reality.
Health NZ has confirmed its own systems were unaffected and directed all questions about patient impact back to ZenTech, a stance that sits awkwardly with its position as a principal under the Act. ZenTech, for its part, did not respond to questions about how many people were affected, describing the number only as “limited.” The 67GB haul suggests the scope may be wider than that framing implies.
The trend behind the headline
ZenTech is not an outlier. It is the most visible recent example of a pattern the NCSC has documented all year. Its Q1 2026 data recorded 1,164 incident reports, direct financial losses of $5.6 million (a 76% jump on the prior quarter), and three “highly significant” incidents, the first since 2021/2022. Q2 2026 saw 92 incidents triaged for specialist support, up 20%, with unauthorised access alone accounting for $1.3 million in losses.
The survival numbers are what should focus minds. Adelphi’s review found 53% of New Zealand businesses reported a cyber incident in 2025, and that 70% of uninsured SMEs in New Zealand and Australia that receive a ransom letter would not survive into the following year.
The NCSC warned in August that third-party suppliers are seen as easier targets where controls are weak. Five weeks later, ZenTech proved the point. The question every leader should now be asking is not whether their own systems are secure, but whether the contractors holding their customers’ data are, and who wears the liability when they are not.
Sources
- Clinical trial company confirms health data impacted in cyberattack (2026-09-18)
- Fears sensitive health files stolen in cyber incident, minister briefed (2026-09-10)
- Sensitive files stolen from Dunedin health tech firm in ‘major’ data breach (2026-09-10)
- Cybersecurity experts raise alarm after back-to-back data breaches (2026-09-11)
- Te Whatu Ora confirms ZenTech cyberattack and investigation (2026-09-10)
- Ransomware group claims cyberattack on Dunedin clinical trial company (2026-09-10)
- New Zealand Clinical Research Company Listed on Emerging ZaWoo Ransomware Leak Site (2026-09-10)
Join the discussion
Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.