Interim relief covers material posted without consent of Health NZ and others
The New Zealand High Court has specified the terms for an interim injunction issued over the data of Health New Zealand and Zenith Technology Corporation Ltd (ZenTech) derived from or obtained in a cyber attack against ZenTech’s servers in or around August 2026.
The case was Health New Zealand / Te Whatu Ora v Unknown Defendants [2026] NZHC 2938. The first plaintiff, Health NZ, engaged the second plaintiff, ZenTech, to perform clinical trials and associated activities from 2013–23.
Late last August, during a cyber attack against ZenTech’s computerised servers, unknown parties accessed and exfiltrated up to 67.1GB of data, digital files, and information owned by the plaintiffs and third parties.
Shortly afterward, ZenTech discovered the encryption of files on its servers with ransomware. ZenTech saw that the hacker left on its servers a text file titled “how to restore your files,” which warned about the publication of the data on the dark web without the payment of ransom.
On 31 August 2026, those responsible for the cyber incident published two file listings on a dark web data leak site, alongside the corresponding data, attributed to ZenTech.
On 4 September 2026, somebody removed the data posted on the dark web. On 9 September 2026, those responsible made the dataset available once more for a brief period before again taking it down.
Early in September, the National Cyber Security Centre (NCSC) informed Health NZ about the ZenTech cyber attack, about the online advertisement of files attributed to ZenTech, and about the ransom request.
As part of its crisis and incident management procedures, Health NZ engaged with police, the NCSC, ZenTech, and other agencies. During the instances when the data was available on the dark web, police copied and preserved the posted material.
Without notice, Health NZ and ZenTech sought an injunction over the use or publication of confidential information unlawfully taken from ZenTech’s servers during the cyber incident.
Despite the unknown volume of data and identities of the files impacted, the plaintiffs claimed that the information was highly sensitive and personal.
Based on the supporting evidence, the High Court of New Zealand ruled that the plaintiffs’ application made out the requirements for an interim injunction, as well as a good, arguable case for a claim of breach of confidence.
The court determined that the overall justice of the case favoured protecting the cyber attack victims, including third parties clearly interested in safeguarding their private information.
The court held that the interim injunction should cover material that should not have been released without the consent of the plaintiffs, individuals, or organisations from whom or about whom it had been collected.
The High Court considered it appropriate to issue a non-publication order over any information identifying the plaintiffs’ individual representatives.
However, the court did not deem it appropriate to make an order redacting confidential and/or personal information believed to be in the affected dataset in any publicly available minute, order or judgment issued in this proceeding.
The court also declined to issue an order suppressing:
Here are some other recent news stories involving Health NZ.
Last month, Privacy Commissioner Michael Webster issued compliance notices to Manage My Health (MMH) and Health NZ for failing to adhere to the security requirements of r 5 of the Health Information Privacy Code 2020 during a cyber incident in late December 2025.
On 27 May 2026, in the results of the first phase of his independent inquiry into the cyber incident, Webster found that MMH and Health NZ breached the Privacy Act 2020.
Enjoy this story? Read the latest TMT (telecoms, media, technology) news on the main page!