September 18, 2026

Stop assuming your contractor’s data security is your liability shield

Data Security Breach

A “cyber incident” became a confirmed privacy breach this week. Dunedin clinical trial company Zenith Technology (ZenTech) has confirmed personal information was compromised in a cyberattack, including health and identifying data collected during clinical trials. The admission arrived not in a press conference but in a public notice buried in Friday’s Otago Daily Times, a week after police began investigating.

ZenTech’s own words were blunt: it understood “some of this information is likely to include health-related and identifying data collected as part of the clinical trial process.” That is a long way from the vague “potential impact” language companies usually hide behind.

A theft model that defeats your backups

The breach first surfaced publicly around 10 September, when files attributed to ZenTech turned up online and Health Minister Simeon Brown was briefed. The ZaWoo ransomware group claimed responsibility, posting sample data purporting to show a patient record with a name, NHI number, address, date of birth, referring doctor and blood test results, then demanding bitcoin under threat of publication.

The technical detail matters for every business leader. Threat intelligence analysis found an internal server was compromised and 67GB of data exfiltrated, with no evidence any of it was encrypted. That points to pure data theft, not traditional ransomware. It is a model that defeats the single most common defence: robust backups. If your files are stolen rather than locked, restoring from backup does nothing to stop them being published. The leverage sits entirely in the threat of exposure.

Health data makes the target doubly attractive. Dr Abhinav Chopra, a cybersecurity expert at the University of Auckland, explained why it commands a premium: “They have information about their bodies and their allergies, they’ve got clinical information, which is information that cannot be changed, so the dataset is quite static and can be used by a number of buyers on the black market.” Unlike a password, a diagnosis cannot be reset.

The liability trap most coverage is missing

Here is the part that should have legal and IT teams talking this week. ZenTech is a contractor. It processes data on behalf of pharmaceutical companies, Health NZ and other health sector principals. Under the Privacy Act 2020, those principals remain legally responsible for how their contractors handle data. A breach at ZenTech is not just ZenTech’s problem.

Adelphi Insurance Brokers’ 2026 cyber market review flags three exposure points for health-adjacent organisations. First, principal liability under the Privacy Act. Second, the 72-hour notification clock, which starts when the contractor becomes aware of a breach, not when the client is told. If ZenTech took days to notify Health NZ, Health NZ’s own obligations were already running down. Third, underwriting misclassification, where contract research organisations holding sensitive health data are not always assessed with a risk profile that matches their true exposure, leaving coverage short of reality.

Health NZ has confirmed its own systems were unaffected and directed all questions about patient impact back to ZenTech, a stance that sits awkwardly with its position as a principal under the Act. ZenTech, for its part, did not respond to questions about how many people were affected, describing the number only as “limited.” The 67GB haul suggests the scope may be wider than that framing implies.

The trend behind the headline

ZenTech is not an outlier. It is the most visible recent example of a pattern the NCSC has documented all year. Its Q1 2026 data recorded 1,164 incident reports, direct financial losses of $5.6 million (a 76% jump on the prior quarter), and three “highly significant” incidents, the first since 2021/2022. Q2 2026 saw 92 incidents triaged for specialist support, up 20%, with unauthorised access alone accounting for $1.3 million in losses.

The survival numbers are what should focus minds. Adelphi’s review found 53% of New Zealand businesses reported a cyber incident in 2025, and that 70% of uninsured SMEs in New Zealand and Australia that receive a ransom letter would not survive into the following year.

The NCSC warned in August that third-party suppliers are seen as easier targets where controls are weak. Five weeks later, ZenTech proved the point. The question every leader should now be asking is not whether their own systems are secure, but whether the contractors holding their customers’ data are, and who wears the liability when they are not.

Sources

Community

Join the discussion

Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.

Create a commenter account

Enter the name you want shown publicly and your email. We will email you a password-set link; you cannot comment until you use it.

Your email is used for sign-in and account security. It is not published with comments.

Subscribe for weekly news

Subscribe For Weekly News

* indicates required