More details have now been released about the recent ransomware attack on Dunedin-based clinical research company ZenTech.
According to media reports, ZenTech was told to pay a ransom in bitcoin and warned, “you may have other file backups, but there is no backup of the customer’s privacy and trust”.
It’s been reported that the cybercriminals say that they have stolen sensitive information belonging to ZenTech clinical trial participants. This information may include peoples’ names, home address, phone number, email address, bank account information, IRD number, passport details, driving licence details, and health & medical records.
This is exactly the sort of information cybercriminals need for identity theft and personalised phishing attacks.
ZenTech is the victim of a cybercriminal attack, but the incident highlights the responsibility that comes with holding sensitive information. Organisations need to understand what data they collect, where it is stored and who can access it. They must also have a well-rehearsed Incident Response Plan that helps them contain an attack, communicate clearly, and support affected people when something goes wrong.
Although unable to comment on specific cyber incidents, a spokesperson for the National Cyber Security Centre said that being a company or organisation targeted by a ransomware attack could be “terrifying” and overwhelming, but NCSC and others would be on hand to help, and having prepared an Incident Response Plan “means that, if and when it happens, you can have a less difficult time getting through it”.