Key Takeaways
- ZenTech has taken some systems offline while cyber forensic specialists investigate the incident and material published online.
- Health NZ says its systems remain unaffected, but police are investigating the suspected theft of clinical-trial files that may contain sensitive health information.
- The case highlights third-party cyber risk across clinical research, where interconnected organizations hold valuable health and pharmaceutical data.
Zenith Technology, the Dunedin clinical research and laboratory testing business known as ZenTech, has taken certain systems offline as authorities investigate a cyber security incident involving files attributed to the company.
Health New Zealand Te Whatu Ora (Health NZ) confirmed that it is supporting the response, which now includes specialist cyber forensic work, police involvement and coordination through established national incident response protocols. The health minister has also been briefed and is receiving regular updates.
The immediate operational picture is mixed but contained, based on current disclosures. ZenTech has said the incident is affecting its operations and that systems were taken offline as a precaution while independent experts secure its IT environment and determine the nature and extent of the intrusion. Health NZ, meanwhile, says its own digital systems are unaffected. Hospitals and primary care providers continue to operate normally.
That distinction matters. ZenTech works with Health NZ and the broader health sector, but there is currently no indication that the incident has moved into Health NZ infrastructure. Even so, a compromise at a clinical-research partner can create substantial exposure without disrupting hospital systems directly.
ZenTech provides clinical-trial and analytical laboratory services to the international pharmaceutical industry. Information held in that environment could include sensitive health data and specialized research material. Police are investigating the suspected theft of a large number of clinical-trial files, although the volume, contents and ownership of any compromised information have not been publicly confirmed.
According to TEISS, the response followed the appearance of material attributed to ZenTech online. ZenTech has acknowledged that sample material purported to be company data was published, but it has not verified the identity of the attacker or confirmed the scope of any theft.
A ransomware group reportedly claimed responsibility in late August, using a dark web blog to set a negotiation deadline for ZenTech and alleged victims in other countries. The group appears to be relatively new to ransomware and data-extortion activity. Its reported ransom note described a financial motive rather than a political one.
For now, that remains an attacker claim, not a completed forensic finding. Dark web postings can provide an early signal of a breach, but criminals also use selective samples, deadlines, and public pressure to strengthen their bargaining position. These negotiation tactics often shape an organization's notification duties and the longer-term impact of a breach.
Clinical research businesses manage highly sensitive data flows. They exchange information with healthcare providers, pharmaceutical sponsors, laboratories, technology suppliers, and trial participants. A single incident can therefore trigger privacy, contractual, regulatory, and research-integrity reviews across several organizations and potentially several jurisdictions.
The broader threat environment adds weight to the ZenTech case. The ENISA Threat Landscape 2025 found that ransomware represented 81% of documented cybercrime incidents in the EU, with healthcare among the sectors targeted most frequently. While the report covers Europe rather than New Zealand, the attacker economics and data-extortion methods cross national boundaries.
A Comparitech healthcare ransomware roundup reported 445 ransomware attacks on hospitals, clinics, and direct care providers in 2025, along with 191 attacks on pharmaceutical manufacturers, healthcare technology businesses, and other related organizations. Confirmed attacks against healthcare providers exposed more than 10.1 million records. Average ransom demands fell to about $615,000 from $3.9 million in 2024, suggesting that lower demands have not translated into lower attack volume.
For business and technology leaders, the practical lesson is less about one security product and more about coordinated readiness. Segmented access, monitored endpoints, tested offline backups, rapid credential resets, and rehearsed communications can help limit damage. Third-party inventories should also identify which partners hold health data, trial records, or intellectual property, and who leads the response if those records appear online.
ZenTech says it is working closely with Health NZ and other authorities and will provide updates after information has been assessed and confirmed. If investigators establish a risk to individuals, Health NZ says it will work with ZenTech and relevant agencies to notify and support those affected. Until the forensic review advances, the central facts remain deliberately narrow: ZenTech is containing an operational incident, police are investigating suspected data theft, and Health NZ’s systems and frontline services remain unaffected.
⬇️