Cybersecurity experts are raising the alarm after back-to-back data breaches at two New Zealand companies.Police are investigating a breach at health research company Zenith Technology, also known as ZenTech, in which a large number of files related to clinical trials may have been stolen.Soon after the ZenTech breach was made public, payroll company Thankyou Payroll notified its users that they had been exposed by a global security breach involving open source analytics tool Metabase.Ben Van Der Weerd, an undergraduate cybersecurity researcher at Victoria University, said both companies made attractive targets."Payroll companies in specific, they have a lot of people on file, they have lot of 'PII' or 'personally identifiable information', and this data goes for a lot of money on the dark web and can enable quite a lot of further attacks and phishing," he explained."Now they know where you live and they've got your IRD number and full name, so they might say 'oh, you didn't pay enough tax on this pay rate exactly 3 months ago under this IRD number, log into the portal to pay your tax' and that would get quite a few people."A company like ZenTech, on the other hand, had high-value data that could be used to negotiate for a ransom."Health companies as well, they're more likely to pay a ransom," he said."If you were hosting a website for your cafe, if you breach that there's not a lot of return for the hackers, but if you breach something that has a lot of people's biological data or financial records, that's going to get you somewhere."The office of ZenTech - Zenith Technology in Dunedin.RNZ / Tess BruntonDr Abhinav Chopra, a cybersecurity expert at the University of Auckland, said even if a ransom couldn't be negotiated, the patient data would be valuable on the dark web, as it was fundamental personal information that couldn't be updated like a password or email address."They have information about their bodies and their allergies, they've got clinical information, which is information that cannot be changed, so the dataset is quite static and can be used by a number of buyers on the black market," Chopra said."So this is data that can get them good money either way, both from ransom or they sell the data on the black market."He said the hackers who targeted ZenTech were previously known to use phishing."From what I've learned about the hackers, the last incident [they were involved in] they did some phishing to get the credentials of a person, and then logged into a privileged account and from there moved to get access to their dataset," he said."But I'm not saying that happened to ZenTech."He said the attack was a reminder that cyber attacks were becoming more likely, even for relatively small companies."We have to be serious about the likelihood [of cyber attacks]. When you do your likelihood-cross-impact, impacts have been high but most of us have been saying, 'oh, well the likelihood is low'. But since the Waikato DHB, all those likelihoods have increased," he said."Many of the controls are pretty cheap to achieve, so just getting an assessment done and then getting onto the quick win kind of layers that you can adopt while you work on a roadmap of how you can get the different other layers into your mix is really helpful."
Cybersecurity experts raise alarm after back-to-back data breaches
Cybersecurity experts are raising the alarm after back-to-back data breaches at two New Zealand companies.
ZenTech and Thankyou Payroll breaches expose clinical and payroll PII—immutable data attracting ransom demands and dark web resale. Breach probability underestimated in risk models; health/payroll firms face growing threat as security spending lags likelihood.








