NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Budget 2025
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Waikato DHB cyber attack: Individual patients could be blackmailed, experts warn

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
24 May, 2021 05:35 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Waikato DHB's IT centre was the target of a major cyber security attack. Video / Waikato DHB

"We don't pay ransom" has been the blunt message from Waikato District Health Board chief executive Dr Kevin Snee as his organisation continues to grapple with the effects of a cyberattack that hit last Tuesday.

The DHB has preferred to with the multi-day - turning into multi-week - grind of restoring its systems from backups.

Police and cyber experts say that's the best approach: If you pay up, you'll only encourage more offending.

And ex-RAF cyber operations expert Jeremy Jones, now with Theta, told the Herald, "I would be highly surprised if all the Waikato DHB records weren't stolen as part of this attack." Photo / Supplied
And ex-RAF cyber operations expert Jeremy Jones, now with Theta, told the Herald, "I would be highly surprised if all the Waikato DHB records weren't stolen as part of this attack." Photo / Supplied
Advertisement
Advertise with NZME.

But security experts also warn that where the likes of a healthcare provider or law firm is the target of an attack, getting its files returned (by backup or payment) is only half the process.

The cyber-attackers can also make copies before unlocking or returning files in order to extort individual patients (or customers).

"There is always the risk that the criminals could contact individual patients to blackmail them, particularly if those patients suffer from ailments that would be embarrassing or they would not want others to be aware of," says Dublin-based security expert Brian Honan.

Honan is head of the Irish Reporting and Information Security Service - billed as Ireland's Cert (Computer Emergency Response Team) - and the country has been in the thick of it.

On May 14, Ireland's public health service was hit by a major ransomware attack, from which it is still recovering. A ransom was not paid. The attackers asked for US$20 million in bitcoin. On May 20, the Financial Times reported that 27 personal files associated with the attack had been posted online. (As well as rendering various services inoperative, the ransomware gang behind the Irish attack, the ContiLocker Team, claims to have stolen 700 gigabytes of data, including patients' home addresses and telephone numbers, as well as staff employment contracts, payroll data and financial statements.)

Advertisement
Advertise with NZME.

"And this has happened in the past where criminals ransomed data in a private psychology clinic in Finland, they also demanded payment not to publish that data onto the internet, and they also extorted individual patients to prevent the publication of their individual files," Honan says.

Waikato DHB chief executive Dr Kevin Snee: "We are dealing in uncharted territory here." Photo / Duncan Brown
Waikato DHB chief executive Dr Kevin Snee: "We are dealing in uncharted territory here." Photo / Duncan Brown

In October 2020, Patients of the Helsinki-based Vastaamo chain of clinics received extortion notes from a ransomware gang, which threatened to publish their therapy notes - which included everything from adultery to LSD use - if they didn't pay €500 within 48 hours to fork over €500, Around 30 paid up. Another 100 - including politicians and celebrities - had embarrassing details spilled on the public internet. Vastaamo was put into liquidation in January.

Discover more

Opinion

Chris Keall: Death of the DHBs a chance to give health tech a new life

21 Apr 05:00 PM
Business

'Foreseeable attacks, critical gaps': Watchdog slams NZX for cybersecurity failures

27 Jan 07:16 PM
Business

Why hackers target hospitals/3 ways our Govt is enabling ransomware

18 May 08:45 PM
New Zealand|crime

DHB attack: 'Good progress' restoring systems and services

23 May 12:44 AM

Waikato DHB boss Snee says it seems there is a low chance that patient records have been exposed. But the DHB boss also said at a press briefing over the weekend that the attack was more far-ranging than first thought. "We are dealing in uncharted territory here," Snee said.

And ex-RAF cyber operations expert, Jeremy Jones, now with Theta, told the Herald, "I would be highly surprised if all the Waikato DHB records weren't stolen as part of this attack."

Jones explained, Cyber adversaries deliver these attacks in spite of any security controls that might be deployed, eg: Anti-virus or firewalls. They simply seize controls of administrative accounts and then disable the security controls one by one, leaving the IT department blind to the attack.

"Since some victims have (rightly) refused to pay the ransom, adversaries ended up changing their tactics. They steal all the data first and then encrypt it. If you refuse to pay then they extort the victim organisation by threatening to release the data publicly."

Why the sudden escalation in attacks on hospitals?

The New York Times recently described a rash of cyberattacks on American hospitals - often by gangs based in Russia - as "their own kind of pandemic".

Hospitals have long been a favoured target for hackers. The life-and-death urgency of restoring files can make it more likely a ransom will be paid (and there can be rich pickings later from shaking down individual patients). But Covid-19 has seen a step-up in tempo.

Advertisement
Advertise with NZME.

"Criminals are targeting healthcare providers because they realise how dependent we are on those providers during the pandemic," Honan says.

"As such they believe the providers' reliance on their IT systems will make it more likely for them to pay any ransom demands.

He adds, "We have to remember that the people behind these attacks are criminals with little or no scruples and look to prey on the most vulnerable in society."

The attackers can be utterly ruthless, if no ransom is paid. In November last year, the University of Vermont Medical Centre couldn't treat some chemotherapy patients because an attack wiped their records. "Nurses said it was one of the worst experiences of their careers," the Times reported.

With lives at stake, or your most embarrassing secrets about to spill onto the web, it must be tempting to pay up (just as the likes of Garmin, Canon, the Colonial Pipeline, Blackbaud and others have capitulated to cyber-extortion in the business world).

But Honan says it's a temptation that has to be resisted, and not just because choking the flow of funds to ransomware gangs incentivises more attacks.

"Criminals by their nature are not trustworthy and there is no guarantee that they won't release the data at a later date, or return again at a later tone demanding another payment, or sell the data to other criminals for them to use that data to target people affected with scams or other online crimes."

War game it

Experts say you should educate your staff to be wary of suspicious emails (the usual conduit for ransomware to infiltrate a network), keep all of your IT systems up-to-date and maintain multiple backups - including a "cold" or offline backup.

The classic mistake here is backing up, but never testing whether it works.

"I recommend regularly testing your restore procedures, running exercises which simulate a ransomware attack, and also including ransomware attacks as part of your business continuity planning."

For his part, Jones said part of the problem is that the 20 DHBs use a patchwork of different security solutions, many of which are outdated or have been band-aided together over time.

That makes it hard for deputy-director general of health Shayne Hunter to control, Jones says (Hunter oversees digital policy for the Ministry of Health).

Our Government - like others, has refused to make paying a cyber ransom illegal - or introduce controls that would prevent bitcoin and other cryptocurrencies being used for anonymous payoffs.

And Budget 2021 was generally short on technology initiatives - certainly, there was nothing close to Australia's recently multi-billion boost for cyber security.

But it did allocate $230m operating spending and $170m capital spending toward the creation of a centralised patient record system over the next four years as the 20 DHBs are merged into a single national health agency. That should make it easier to shore up the system's defences.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Business

Syos wins company of the year crown, Beck named Flying Kiwi

23 May 11:00 AM
Premium
Media Insider

Breakfast battle: Hosking v Barnett ratings and Bridge is back; RNZ cuts: What's in line?

23 May 08:10 AM
Premium
Shares

Market close: NZ sharemarket falls as interest rates take centre stage

23 May 06:11 AM

Deposit scheme reduces risk, boosts trust – General Finance

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Syos wins company of the year crown, Beck named Flying Kiwi

Syos wins company of the year crown, Beck named Flying Kiwi

23 May 11:00 AM

Deep Dive Division was also among the big winners at the annual Hi-Tech Awards.

Premium
Breakfast battle: Hosking v Barnett ratings and Bridge is back; RNZ cuts: What's in line?

Breakfast battle: Hosking v Barnett ratings and Bridge is back; RNZ cuts: What's in line?

23 May 08:10 AM
Premium
Market close: NZ sharemarket falls as interest rates take centre stage

Market close: NZ sharemarket falls as interest rates take centre stage

23 May 06:11 AM
Agritech leaders say Budget offers tax relief but lacks bold vision

Agritech leaders say Budget offers tax relief but lacks bold vision

23 May 04:01 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP