MERCOLA Listed by blackbasta Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The MERCOLA Listed by blackbasta Ransomware Group (reported October 12, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In October 2022, the organisation MERCOLA appeared on a ransomware group's leak site, with the group claiming it had taken internal files. For customers, employees, or partners whose information may sit inside those systems, the practical stakes are straightforward: unknown volumes of internal material may have left the organisation's control, and public detail on exactly what was taken remains limited.
The listing itself does not automatically confirm every claim a threat actor makes, yet it is a signal that people connected to MERCOLA should treat seriously. When internal files are said to have been exfiltrated, the risk is not abstract; it can include business records, correspondence, or other material that later surfaces in unwanted places. This article sets out only what has been reported, what is known about the actor, and what steps affected people can reasonably take.
Breaking down the breach
According to reporting dated October 12, 2022, MERCOLA was listed on the blackbasta ransomware leak site. The group claims to have stolen internal data and describes the material as internal files exfiltrated in a ransomware attack. The number of people affected is unknown. No public figure has been given for the volume of data, the precise date of intrusion, or the technical method used to gain access. Those details remain undisclosed in the available record.
What is stated is limited to the leak-site listing and the group's assertion that internal files were taken. There is no independent confirmation in the provided facts that the full contents of any claimed archive have been verified by outside parties, nor is there a disclosed timeline of when systems were first compromised or when encryption, if any, occurred. In short, the incident is known through the group's public claim and the organisation's appearance on the leak site; scale, method, and full contents are not detailed in the public summary.
Who is blackbasta?
Blackbasta is a ransomware operation that became widely documented in 2022. Like other groups in the same category, it has typically used a double-extortion model: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. The group has been observed listing victims on a dedicated leak site and releasing samples or larger archives when negotiations stall. Public reporting has linked blackbasta to attacks across multiple sectors, often after initial access obtained through compromised credentials, phishing, or exploitation of exposed services, followed by lateral movement and data staging before ransomware deployment.
None of that general pattern should be read as a confirmed playbook for this specific case. For MERCOLA, the facts state only that the organisation was listed and that the group claims to have stolen internal data. Any further assertion about how the intrusion occurred, what ransom was demanded, or whether data was actually published in full would go beyond the reported record. The leak-site listing is therefore treated here as the group's claim, not as independently verified proof of every detail.
About MERCOLA
MERCOLA is a well-known name in the natural-health and consumer-wellness space, associated with health information, dietary supplements, and related products sold directly to the public. Organisations of this type commonly maintain customer accounts, order and shipping records, marketing lists, employee and contractor information, and internal business documents. They may also hold payment-related records, support correspondence, and proprietary content or research materials.
A breach involving internal files at such an organisation is consequential because the same systems that support day-to-day commerce and communication often concentrate personal and commercial data in one place. Even when the exact inventory of taken files is unknown, the potential reach includes people who bought products, subscribed to communications, or worked with the company. The impact is not limited to brand reputation; it extends to the ordinary privacy and fraud risks that follow when internal material leaves controlled environments.
What data was at risk
The reported facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as customer databases, financial records, health-related details, or employee files—is provided. The number of individuals affected is unknown, and the precise contents of the claimed haul are unconfirmed.
Organisations in MERCOLA's sector typically hold customer contact details, purchase histories, account credentials or password hashes, employee records, and internal operational documents. It is reasonable to note those categories as the kinds of data such a business might possess. It is not reasonable to state that any specific category was definitively taken in this incident. Public detail is limited to the group's claim of internal files; everything beyond that remains undisclosed.
The real-world impact
For individuals, the concrete risks depend on what those internal files actually contained. If contact information, account data, or identity-related fields were included, people may face targeted phishing, credential stuffing, or social-engineering attempts that reference real relationships with the company. If employee or partner documents were involved, similar risks can extend to workplace identity fraud or business-email compromise. Because the scale and exact data types are unknown, no one outside the investigation can yet map every affected person; the prudent stance is to assume that anyone with a meaningful relationship to MERCOLA could be in scope until clearer inventories appear.
For the organisation, a ransomware listing brings operational disruption, potential regulatory and contractual scrutiny, and the long tail of customer support and trust repair. Even when encryption is reversed or systems are restored, the exfiltration claim means the data-control problem does not end with recovery of uptime. The absence of confirmed counts or file lists does not reduce the need for careful notification and monitoring; it simply means those steps must proceed with incomplete public information.
If your data was in this claimed breach
If you have been a customer, employee, or partner of MERCOLA, treat the October 2022 listing as a prompt to tighten basic hygiene rather than as proof that your specific records were published. Practical first steps include:
- Change passwords on any MERCOLA-related account and on other sites where you reused the same password; enable multi-factor authentication where available.
- Watch for phishing or unexpected messages that reference orders, health products, or internal company details; verify through official channels before clicking or replying.
- Review bank and card statements for unfamiliar charges if you ever stored payment methods with the organisation.
- Consider a credit or identity-monitoring freeze if you later learn that sensitive identity documents were involved; that detail is not confirmed here.
- Run a free exposure scan of your email address to check whether it has already appeared in known breach datasets, and treat any hit as a reason to rotate credentials on related services.
Public reporting on this incident remains thin. The group claims internal files were stolen; the number of people affected and the full contents are undisclosed. Staying alert to official notices from MERCOLA, and reducing reuse of passwords and personal data across sites, remains the most useful response while further detail is limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Blairex Laboratories, Inc. Listed by blackbasta Ransomware GroupWipro HealthPlan Services Listed by blackbasta Ransomware Groupmedicacorp.com Listed by blackbasta Ransomware Groupusdermpartners.com Listed by blackbasta Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the MERCOLA Listed by blackbasta Ransomware Group →
Publicly posted by blackbasta — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.