A ransomware group has claimed responsibility for a cyberattack on a Dunedin clinical trial company, with large volumes of sensitive health data feared stolen and Health Minister Simeon Brown receiving regular updates on the breach.
Health New Zealand (Health NZ) confirmed September 10 that it is supporting Zenith Technology (ZenTech) after files attributed to the company were identified online. Police are investigating.
“We are in the early stages of our investigation and are working alongside Health NZ,” a Police spokesperson told Stuff.
According to websites that monitor cyberattacks, a ransomware group publicly claimed responsibility at the end of August on its dark web blog and gave ZenTech – and alleged victims in other countries – a deadline to negotiate, Stuff reported.
New Zealand threat intelligence site threatintel.co.nz published a screenshot of a ransom note apparently sent to some victims, which included the message: “We are not a politically motivated group and want nothing but financial rewards for our work.”
The group appears to have informed victims their files were encrypted and demanded Bitcoin payment for a decryption tool. Stuff has chosen not to identify the group.
ZenTech confirmed it “is currently responding to a cyber security incident affecting its operations” and has taken certain systems offline as a precaution.
“We are aware that some sample material purported to be company data has been published online. As a matter of priority, we have engaged independent cyber security experts to investigate the incident and assess the nature and extent of any impact,” a ZenTech spokesperson said.
A staff member at the company’s office told Stuff: “We are investigating everything, and doing our best – and please remember, we are the victims here.”
ZenTech was founded in 1987 and provides clinical trial and analytical laboratory services for the international pharmaceutical industry. Its website states it has conducted over 500 clinical studies of various types, including first-in-human trials, and regularly recruits participants through social media and student publications – meaning the company holds personal health data on individuals who enrolled in trials, in addition to data related to its pharmaceutical clients and work with Health NZ.
Health NZ said its own digital systems are unaffected. Asked whether individuals would be notified, a spokesperson said: “Where any information is confirmed that indicates risk to individuals, Health New Zealand will work with the impacted organisation and relevant agencies to ensure appropriate steps are taken to notify and support those affected.”
A spokesperson for Brown confirmed he is continuing to receive regular updates on the incident.
The ZenTech incident became public 37 days after the National Cyber Security Centre (NCSC) released supply chain security guidance for organisations that use third parties to store data – citing a pattern of third-party supplier incidents earlier in 2026 as its reason for doing so.
“This sensitive data is attractive to cyber criminals as it can be used to extort the companies responsible or the individuals concerned, and third party suppliers may be considered an easier target if adequate cyber security controls have not been implemented,” the NCSC said on August 4.
The attack lands in a market where ransomware costs are climbing. Adelphi Insurance Brokers’ 2026 cyber market review found that 53% of New Zealand businesses reported suffering a cyber incident in 2025. While ransomware claim frequency saw a slight decrease that year, severity and associated costs increased – driven primarily by business interruption losses. The review also cited one insurer’s finding that 70% of uninsured SMEs in New Zealand and Australia that received a ransom letter would not survive into the following year.
That figure is relevant context for the class of organisations ZenTech represents: specialist, privately owned companies holding significant volumes of sensitive data, but without the IT infrastructure of large health system operators.
For brokers with health-adjacent clients, the ZenTech case raises three coverage questions worth revisiting.
The first is policy scope. Under the Privacy Act 2020, a principal organisation remains legally responsible for personal data held by a contractor. The Office of the Privacy Commissioner’s (OPC) guidance on third-party providers makes clear that the 72-hour notification clock starts when the contractor becomes aware of a breach – not when it informs the client. A policy that only responds when the client’s own systems are compromised may not reflect where the actual exposure sits.
The second is breach response plan timing. Clients whose plans start the notification clock on their own discovery – rather than the contractor’s awareness – may face regulatory consequences for delays outside their control.
The third is underwriting classification. Contract research organisations, clinical trial coordinators, and health IT vendors hold the type of data the NCSC has directly identified as a target for extortion. That risk profile is not always reflected in how these clients are assessed and rated.
Health NZ said the response is being managed through established national incident response protocols. “The right agencies and specialist experts are involved,” the organisation said.
ZenTech said it will provide further updates as more information becomes available.