B2Bnews.Co.Nz ZaWoo Ransomware Group Targets Zenith Technology in Data Breach
Article Content
- •Zenith Technology confirmed a data breach affecting sensitive health data.
- •ZaWoo ransomware group claimed responsibility and demanded Bitcoin for decryption.
- •67GB of data, including personal health information, was exfiltrated from Zenith's servers.
Zenith Technology, a Dunedin-based clinical trial company, has confirmed a cyberattack by the ZaWoo ransomware group, which resulted in the theft of sensitive health data. The attack was first reported on September 10, 2026, when files attributed to Zenith appeared online. The group claimed responsibility for the breach, demanding a ransom in Bitcoin while threatening to publish stolen data. Health New Zealand is assisting Zenith Technology, which has taken certain systems offline as a precaution. The breach involved the compromise of an internal server, with 67GB of data exfiltrated, including personal health information. The incident has raised concerns about compliance with the Privacy Act 2020, as Zenith processes data for various health sector principals. Police are currently investigating the matter, and the company is engaging cybersecurity experts to assess the situation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track ZaWoo and Health New Zealand in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…