polyflor.co.nz Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The polyflor.co.nz Listed by lockbit3 Ransomware Group (reported December 19, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
When a company appears on a ransomware group’s leak site, the people connected to it — staff, suppliers, customers, and partners — face a practical question: could internal files that mention them now be in someone else’s hands? In mid-December 2022, polyflor.co.nz was listed by the group known as lockbit3, which claimed that internal files had been taken in a ransomware attack. How many people were affected, and exactly what sat inside those files, has not been publicly detailed. For anyone who has dealt with the firm, that uncertainty is the core of the problem.
Public reporting on the incident is limited. What is known is the claim itself, the date it was reported, and the broad description of material said to have been exfiltrated. The rest remains undisclosed. Understanding the claim, the actor behind it, and the kind of organisation involved helps put the risk in proportion without overstating what has been confirmed.
Inside the incident
According to public breach records, polyflor.co.nz was listed by the lockbit3 ransomware group on or around 19 December 2022. The group’s claim is that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published. The precise method of intrusion, the duration of any access, whether systems were encrypted as well as copied, and whether any ransom was demanded or paid are all undisclosed in the available record.
Ransomware incidents of this type typically involve unauthorised access followed by theft of data and, often, a threat to publish it if demands are not met. In this case, the public detail stops at the leak-site listing and the description of “internal files.” There is no independent confirmation in the provided facts that the files were released, nor any inventory of what they contained. Readers should treat the listing as a claim by the group rather than as a fully verified account of the breach’s scope.
The group behind it: lockbit3
LockBit is a well-documented ransomware operation that has appeared in many public incident reports over recent years. The “lockbit3” moniker refers to a major iteration of that operation. Groups of this kind commonly run a Ransomware-as-a-Service model: affiliates gain access to networks, deploy the encryptor, and exfiltrate data, while the core operation maintains leak sites and negotiation channels. A frequent tactic is double extortion — threatening both to withhold decryption keys and to publish stolen data — to increase pressure on the victim.
LockBit affiliates have historically targeted organisations across many countries and sectors, often advertising victims on a dedicated leak site when talks stall or to demonstrate capability. Public reporting has linked the brand to large volumes of claimed victims and to repeated updates of its tooling and branding. None of that background, however, proves the specific contents or scale of any single listing. For polyflor.co.nz, the facts support only that lockbit3 claimed the organisation and described internal files as having been taken. Claims made on leak sites are not independent audits; they are assertions by the actors involved.
polyflor.co.nz and its sector
Polyflor is known as a supplier of vinyl and related flooring products for commercial and residential use. The organisation’s own public description emphasises design for better indoor and outdoor environments and a range of flooring suitable for varied applications. Firms in this sector typically sit in manufacturing, distribution, and trade supply chains. They deal with architects, contractors, retailers, facilities managers, and end customers, and they maintain the ordinary corporate systems that support sales, logistics, finance, and product information.
A breach at a flooring manufacturer or distributor is consequential because such companies hold more than product catalogues. They commonly retain employee records, customer and supplier contact details, order and invoice history, contracts, and internal operational documents. Even when a firm is not a household consumer brand, the people and businesses in its orbit can be exposed if internal files leave the organisation’s control. The New Zealand domain indicates a local market presence; the practical impact depends on which systems and which counterparties were reflected in any stolen material — details that remain unconfirmed here.
What data was at risk
The available facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types — such as names, contact details, financial records, or credentials — is provided. The number of people affected is listed as unknown. Exact contents are therefore unconfirmed.
Organisations of this kind typically hold human-resources information, customer and supplier databases, email archives, commercial contracts, and operational documents. Ransomware operators often prioritise material that can be used for extortion or resale. That pattern is general industry knowledge; it is not evidence of what was or was not present in this specific case. Until a fuller disclosure appears from the organisation or from reliable independent reporting, any list of exposed fields would be speculation.
What's at stake
For individuals, the main risks are secondary misuse of personal or contact information if it was present in the taken files: phishing that references real business relationships, social-engineering attempts against staff or customers, or longer-term exposure if documents surface later. For suppliers and commercial partners, contract terms, pricing, or project details could create competitive or privacy concerns. None of these outcomes is confirmed by the public record; they are the ordinary consequences that follow when internal corporate files are claimed stolen.
For the organisation, a ransomware claim can mean operational disruption, investigatory and recovery costs, legal and regulatory obligations, and damage to trust with customers and partners. Because the scale and content of the alleged exfiltration are undisclosed, the severity for polyflor.co.nz specifically cannot be measured from the listing alone. The listing itself is a signal that the group sought leverage; it is not a full incident report.
What to do if you're exposed
If you have worked for, supplied, or bought from polyflor.co.nz, treat the situation as a prompt for ordinary hygiene rather than panic. Watch for unexpected emails or calls that reference the company or recent orders; verify any request for money, credentials, or personal data through a separate known channel. Prefer unique passwords and multi-factor authentication on email and financial accounts so that a single leaked credential is less useful. If you receive notice from the company, follow its instructions and keep records of any correspondence.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That check will not prove whether your data was in this particular incident, but it can show whether your address is circulating more widely and help you prioritise password changes and monitoring. Stay alert to official updates from the organisation; public detail on this listing remains limited, and further clarity, if it comes, will most usefully come from verified sources rather than from the group’s claims alone.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
presco.com Listed by lockbit3 Ransomware Groupbavelloni.com Listed by lockbit3 Ransomware Groupmaxionwheels.com Listed by lockbit3 Ransomware Groupcatalyst-group.co.nz Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the polyflor.co.nz Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.