LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › mercuryit.co.nz Listed by lockbit3 Ransomware Group

HIGH severityUnverified claimHow we verify

mercuryit.co.nz Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 19, 2022
mercuryit.co.nz Listed by lockbit3 Ransomware Group

Reported December 19, 2022.

HIGH
Severity
December 19, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The mercuryit.co.nz Listed by lockbit3 Ransomware Group (reported December 19, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

When an IT services provider that works with companies across New Zealand and Australia appears on a ransomware group's leak site, the practical concern is straightforward: internal files and customer-related data may have been taken or locked. For staff, clients, and anyone whose information sat in those systems, the immediate questions are what may have been exposed, whether personal or business details are involved, and what steps make sense while public detail remains limited.

On 19 December 2022, mercuryit.co.nz was listed by the group known as lockbit3. The listing describes a ransomware attack in which internal files were allegedly exfiltrated and a large volume of customer data was claimed to have been encrypted. The number of people affected has not been published, and independent confirmation of the full scope is not part of the available record.

What happened

Public reporting on this incident centres on a leak-site listing dated 19 December 2022 that names mercuryit.co.nz. According to the group's own summary, the organisation provides IT services to many companies in New Zealand and Australia, and the attackers asserted that they had encrypted more than 500 TB of customer data after an attack in which internal files were exfiltrated. No independent verification of that volume, of the exact method of intrusion, or of a full inventory of what left the network has been supplied in the facts available here. The number of individuals or organisations affected remains unknown. In short, the incident is documented principally through the ransomware group's claim that a double-extortion style attack—encryption plus data theft—took place against this provider.

Inside lockbit3

LockBit3 is a well-documented ransomware operation that has appeared repeatedly in public reporting since earlier LockBit iterations. Groups operating under this banner typically run a ransomware-as-a-service model: affiliates gain access to victim networks, deploy encryptors, and often exfiltrate data before encryption so they can threaten publication if a ransom is not paid. Listings on dedicated leak sites are a standard pressure tactic; they serve both as proof-of-compromise claims and as a way to advertise stolen material. LockBit-branded activity has historically targeted a wide range of sectors and geographies, frequently focusing on organisations whose downtime or data exposure would create operational or reputational cost. None of that general pattern, however, proves every specific claim a listing makes about a single victim. In this case, the assertion that mercuryit.co.nz suffered encryption of more than 500 TB of customer data and exfiltration of internal files should be read as the group's claim, not as independently established fact.

Who is mercuryit.co.nz?

mercuryit.co.nz is presented in the available material as an IT services company serving numerous businesses in New Zealand and Australia. Organisations of this type commonly manage infrastructure, cloud or on-premises systems, support contracts, and sometimes hold credentials, configuration data, backups, or customer records on behalf of clients. Because an IT provider sits in the middle of other companies' operations, a compromise can extend beyond the provider's own staff to the clients who rely on those services. That intermediary role is why a listing of this kind draws attention: the blast radius may include not only the named organisation but also the businesses and individuals whose data or systems it touches. Public detail beyond the group's description and the organisation's sector role is limited.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. The group's summary further claims encryption of more than 500 TB of customer data. No itemised breakdown—such as names, contact details, financial records, credentials, or specific client files—has been disclosed in the record provided. For an IT services firm, typical holdings can include system documentation, support tickets, authentication material, backup sets, and business information belonging to customers; whether any particular category was taken in this incident is unconfirmed. Readers should treat the exact contents as unknown until corroborated by the organisation or by regulators, and should not assume a full public inventory exists.

Why it matters

For people and businesses that used mercuryit.co.nz, the concrete risks are familiar from other ransomware events involving service providers. Stolen internal files can contain enough context to enable follow-on phishing, credential stuffing, or social engineering. If customer data was among what was copied, affected parties may face identity or account misuse, unwanted contact, or exposure of commercial information. For the organisation itself, encryption claims point to possible operational disruption, recovery costs, and the need to notify clients and authorities under applicable privacy rules in New Zealand and Australia. Because the count of affected people is unknown and the precise data types beyond "internal files" and the group's customer-data claim are not verified, the prudent stance is caution without assuming the worst-case scenario as proven. The incident also illustrates the wider dependency risk: when a shared IT provider is hit, many downstream organisations may need to review their own exposure even if they were not the direct target.

Were you affected?

If you are a client, employee, or partner of mercuryit.co.nz, contact the organisation through official channels for any notification or guidance they have issued. Monitor accounts for unusual activity, enable multi-factor authentication where available, and treat unexpected messages that reference the incident with scepticism. Consider placing fraud alerts or credit monitoring if you believe personal identifiers may have been involved, and follow advice from local privacy or cybersecurity authorities in New Zealand or Australia as applicable. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which can help you prioritise password changes and further monitoring while official details remain limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companymercuryit.co.nz security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See mercuryit.co.nz’s full breach history →

More recent breaches

apeagers.au Listed by lockbit3 Ransomware GroupJanuary 31, 2024accuro.co.nz Listed by lockbit3 Ransomware GroupDecember 19, 2022businesscentral.org.nz Listed by lockbit3 Ransomware GroupDecember 19, 2022polyflor.co.nz Listed by lockbit3 Ransomware GroupDecember 19, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the mercuryit.co.nz Listed by lockbit3 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram