accuro.co.nz Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The accuro.co.nz Listed by lockbit3 Ransomware Group (reported December 19, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In December 2022, the New Zealand health insurer Accuro appeared on a ransomware group's leak site, raising immediate questions for anyone whose personal or membership details might sit in the organisation's systems. When an insurer that serves tens of thousands of members is named in such a listing, the practical concern is straightforward: internal files said to have been taken could contain information that affects real people, from contact details to claims history.
Public reporting at the time confirmed little beyond the listing itself and the claim that internal files had been exfiltrated. The number of people affected remains unknown, and many operational details have not been disclosed. For members and others who deal with Accuro, that limited visibility is itself part of the problem—uncertainty about what, if anything, left the organisation's control.
What happened
On or around 19 December 2022, the domain accuro.co.nz was listed by the LockBit3 ransomware group. According to the available record, the group claimed that internal files had been exfiltrated in a ransomware attack. No confirmed figure for the volume of data, no list of specific file names, and no independent verification of the claim have been supplied in the public facts. The number of people potentially affected is recorded as unknown. Timing of the underlying intrusion, the precise method of access, and whether any ransom demand was paid or negotiations occurred are all undisclosed.
What is established is only the listing and the characterisation of the material as internal files taken during a ransomware incident. Beyond that, public detail is limited.
Who is lockbit3?
LockBit3 is the name associated with a prolific ransomware operation that has appeared repeatedly in public reporting since earlier iterations of the LockBit brand. Groups operating under this banner typically gain access to an organisation's network, encrypt systems to disrupt operations, and exfiltrate copies of data so they can threaten to publish or sell the material if a ransom is not paid. They maintain leak sites where they post victim names and, in some cases, samples or larger archives of stolen files to increase pressure.
The model is well documented across many incidents worldwide: double-extortion tactics that combine operational disruption with the threat of data exposure. LockBit affiliates have targeted organisations of widely varying sizes and sectors. In the present case, the appearance of accuro.co.nz on the group's listing should be treated as a claim by the actors rather than as independently confirmed fact. No further statements attributed specifically to LockBit3 about this victim appear in the provided record.
accuro.co.nz and its sector
Accuro is a New Zealand-owned, not-for-profit health insurer. Its own description emphasises putting roughly 30,000 members ahead of financial gain, offering insurance products, relatively fast claims handling, and customer service. As a health insurer it sits in a sector that routinely handles sensitive personal and medical-related information in the course of underwriting, membership administration, and claims processing.
Organisations of this type are consequential targets precisely because the data they hold is tied to individuals' health cover, financial arrangements with the insurer, and often identity particulars needed to manage policies. A breach affecting such an entity can therefore reach beyond the company itself to the people who rely on it for cover. The not-for-profit, member-focused character of Accuro does not change the sensitivity of the information an insurer typically maintains; it simply underscores that the people most directly concerned are ordinary members rather than large commercial clients.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as names, addresses, dates of birth, membership numbers, claims records, payment details, or medical information—is provided. Exact contents therefore remain unconfirmed.
In general, a health insurer in New Zealand would be expected to hold membership and contact data, policy and premium information, claims submissions and related correspondence, and whatever identity or health-related particulars are required to administer cover and meet regulatory obligations. Whether any of those categories were present in the files LockBit3 claimed to have taken is not established by the public record. Readers should treat the exposure as involving unspecified internal material rather than any named category of personal data.
What's at stake
For individuals, the core risk is that personal information—if it was among the internal files—could be misused for fraud, social engineering, or unwanted contact. Even limited identity or membership details can be combined with other data sources to craft convincing scams. Health-related or claims information, should any have been included, carries additional sensitivity because it touches on private circumstances. Because the scale and exact contents are unknown, people connected to Accuro cannot easily judge their personal exposure from public sources alone.
For the organisation, a ransomware incident and a leak-site listing create operational, reputational, and regulatory pressures. Restoring systems, investigating the intrusion, notifying affected parties where required, and managing member trust all carry cost and disruption. The absence of confirmed numbers or a detailed inventory of what left the environment prolongs uncertainty for everyone involved.
Were you affected?
If you are a current or former Accuro member, or have otherwise shared personal information with the insurer, treat the incident as a prompt to review your own exposure. Monitor bank and credit activity for unfamiliar transactions, be cautious of unexpected emails or calls that reference insurance or personal details, and consider placing fraud alerts where appropriate. Change passwords on related accounts if you reuse credentials, and enable multi-factor authentication where it is offered.
You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can indicate whether your details have surfaced elsewhere and help you prioritise further precautions. Public detail on the Accuro listing remains limited; staying alert to official notices from the organisation itself is the most direct way to learn of any confirmed impact.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
thedonovancompany.com Listed by lockbit3 Ransomware Groupbusinesscentral.org.nz Listed by lockbit3 Ransomware Grouppolyflor.co.nz Listed by lockbit3 Ransomware Groupcatalyst-group.co.nz Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the accuro.co.nz Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.