A cyberattack on Zenith Technology has triggered a police investigation and a coordinated government response amid concerns sensitive health data may have been exposed.
Ransomware group claims breach at Dunedin clinical research firm ZenTech
Zenith Technology, a Dunedin-based clinical research and laboratory testing company known as ZenTech, is responding to a cyber security incident that has prompted a police investigation and government-led coordination, Health New Zealand Te Whatu Ora (Health NZ) confirmed Thursday.
Health NZ, the country’s public health agency, said it is supporting ZenTech’s response and that the company has engaged specialist cyber forensic experts. The agency said it learned of the incident after files attributed to ZenTech were found online.
ZenTech is a privately owned company that provides clinical-trial and analytical laboratory services to the international pharmaceutical industry and works with Health NZ and the broader health sector.
Health NZ said its own digital systems are unaffected and that hospitals and primary care providers continue to operate normally. The agency did not disclose how many files, or what type, may have been compromised, saying the response is being managed through established national incident response protocols.
Police are investigating the incident, which is suspected to involve the theft of a large number of files related to clinical trials, including sensitive health information. Health NZ said there are limits on what can be publicly disclosed while the police investigation and forensic work continue.
If information is confirmed that indicates a risk to individuals, Health NZ said it would work with ZenTech and relevant agencies to notify and support those affected.
Health Minister Simeon Brown has been briefed on the incident and continues to receive regular updates, his office said.
A ransomware group reportedly claimed responsibility for the attack in late August, posting on a dark web blog and setting a deadline for ZenTech and alleged victims in other countries to negotiate. The group appears to be new to ransomware and data-extortion operations, and a ransom note it reportedly sent stated it was not politically motivated and sought only financial gain.
ZenTech has not confirmed the identity of the group or the scope of any data taken.
A company spokesperson said ZenTech is responding to a cyber security incident affecting its operations and has taken certain systems offline as a precaution while it works to secure its IT environment and contain the incident. The company said it is aware that sample material purported to be company data has been published online and has engaged independent cyber security experts to investigate the incident’s nature and extent.
ZenTech said it is working closely with relevant authorities, including Health NZ, and will provide further updates once information has been assessed and confirmed as accurate.
A staff member at the company’s office said Thursday that ZenTech had been advised by its lawyer not to comment further, adding that the company considers itself a victim in the incident and is investigating fully.
