A Dunedin clinical trial operator has confirmed that health and identifying data from its studies was taken in a cyberattack – and it chose a small newspaper notice, not a press release, to say so.
Zenith Technology, trading as ZenTech, admitted the compromise about a week after police opened an investigation. Its notice conceded that the stolen material likely includes clinical trial information that is both health-related and identifying. The ZaWoo extortion crew took credit, publishing a sample record that combined a patient’s identity details with lab results and threatening to release more.
Forensics pointed to an internal server and roughly 67GB of exfiltrated files, none of them encrypted. That distinction matters beyond this case: when intruders steal files instead of locking them, backups offer no protection against publication.
Contractor exposure compounds the damage. ZenTech processes trial data for drug developers and Health New Zealand, and under the Privacy Act 2020 those principals remain accountable for how a vendor handles it. The 72-hour notification clock starts when the contractor learns of a breach, not when its client is told.
Health New Zealand says its own systems were untouched. ZenTech calls the number of affected patients “limited” but has declined to quantify it – a framing that fits awkwardly with a 67GB haul.