NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

10-day countdown: Ransomware gang posts $1.5m demand for files stolen from provider to Health NZ, Coroners Court, others

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
19 Dec, 2022 11:50 PM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Image / 123RF

Image / 123RF

A gang called LockBit has posted a series time-pressure demands for money on the dark web, claiming to have files from clients to Wellington-based IT provider Mercury IT - which was hit by a ransomware attack in late November, according to the Privacy Commissioner.

The attack compromised data from Mercury IT clients including contractors to Health NZ, some 14,500 coronial files and 4000 post-mortem reports according to the Ministry of Justice, the NZ Nurses Association (which represents 55,000 healthcare workers), BusinessNZ, the Wellington Chamber of Commerce and the affiliated Business Central, and some 30,000 customers of Wellington-based private health insurer Accuro.

LockBit is demanding US$999,999 ($1.54 million) within 10 day for files it says it has from Mercury IT. As of 4am this morning NZT, the gang’s counter had nine days and 20 hours left), according to Brett Callow, threat assessment analyst with Emsisoft - an NZ-based firm helping organisations grapple with ransomware attacks.

The gang was also demanding US$999,999 ($1.5m) for files from Mercury IT, US$199,999 for files from Business Central and US$99,999 for files from Accuro.

Advertisement
Advertise with NZME.

The Herald understands other organisations caught in the attack are also being shaken down.

It does not necessarily mean files from Mercury IT clients will be released onto the dark web if the firm (or clients) fail to cough up with 10 days.

Callow explains that LockBit’s modus operandi is to offer stolen files to all comers.

Mercury IT could pay US$999,999 to regain access to its files, with LockBit - supposedly - destroying any copies.

Advertisement
Advertise with NZME.

If another party - such as a cyber fraud or blackmail outfit - pays the US$999,999 before Mercury, then it gets the files.

But if no party pays the sum, then the countdown clock can be restarted.

Discover more

Business

Chris Keall: The Government’s Digital Council dies, as it was born, in high farce

15 Dec 04:00 PM
Business

'Still a lot to be done' - Muted industry reaction to tech policy in Budget 2022

19 May 05:50 AM
Official Cash Rate

Revealed: The number of Kiwi businesses that would pay a cyber ransom

29 May 05:00 AM
Business

Spy agency says 170,000 cyberattacks launched on NZ

19 Sep 05:35 AM

LockBit also offers victims the chance to pay a smaller sum to extend the deadline by another 24 hours, or another week.

The GCSB’s National Cyber Security Centre is leading a multi-agency investigation. The agency had no update this morning bar that it continued to work with organisations impacted by the Mercury IT breach.

Accuro: ‘Taking steps’

“We are making no comment on the ransom,” Accuro chief executive Lance Walker told the Herald this morning, when asked about LockBit’s US$99,999 demand.

It marked the first time his firm had used the “r” word. (It was new Privacy Commissioner Michael Webster who outed it as a “ransomware attack” on December 6 as he revealed his office planned to open a compliance investigation).

Walker, whose firm has previously refused to say if it is in ransom negotiations or not (a different policy from the Waikato DBH last year, which ruled it out), declined further comment.

In a statement posted to Accuro’s website this morning, after the Herald’s initial article, Accuro reiterated it was “aware that the third-party responsible for the cyber-security incident impacting Mercury IT, has disclosed some information belonging to Accuro online.

Advertisement
Advertise with NZME.

Walker said in the statement, “We are assessing the data to determine who the information belongs to and taking steps to have the disclosed information removed where possible.”

Customers whose data had been compromised would be contacted, and advised.

Walker reiterated that his firm had cyber-security and forensic IT experts and was working with Government agencies.

High Court order

Mercury IT declined comment today. The Herald is seeking comment from other organisations involved in the November hack - but there has already been a sign that government agencies are aware of any immediate risk of files being spilled into the public domain.

Last week a High Court judge issued a blanket order compelling anyone who may have received hacked health data or coronial inquest files - or any client files spilled in the Mercury IT breach - to immediately delete them. The order extended to media.

The order by Justice Christine Grice said anyone who received the files or who may receive the files in the future cannot access, look through or filter the records in any way.

Callow said he did not seek to access any “taster” files offered by LockBit, mindful of a court order.

LockBit arrest

While it’s rare for ransomware attackers to be brought to justice - in part because many operate from Russian or Eastern European countries with limited cooperation with the West - there was a recent arrest involving LockBit’s alleged global ransomware campaign.

A criminal complaint filed in the District of New Jersey was unsealed on November 10, charging a dual Russian and Canadian national for his alleged participation in the LockBit global ransomware campaign, according to a US Justice Department statement.

Mikhail Vasiliev, 33, of Bradford, Ontario, Canada, is in custody in Canada and is awaiting extradition to the United States.

“This arrest is the result of over two-and-a-half-years of an investigation into the LockBit ransomware group, which has harmed victims in the United States and around the world,” said Deputy Attorney General Lisa Monaco said. BitLock first emerged in January 2020.

The arrest does not appear to have crimped LockBit. Six days ago, with Vasiliev still awaiting extradition, the gang claimed to have stolen 76GB of data from the California Department of Finance, including databases, confidential information, financial and IT documents and, cryptically, “sexual proceedings in court”.

While US authorities managed to produce enough evidence to gain a warrant for Vasiliev’s arrest, Callow says “not all of LockBit’s past claims have been true”.

Privacy Commissioner leans toward change

Emsisoft’s Callow is among those who have suggested circuit-breaker moves to stop the relentless waves of ransomware, including making it illegal to pay a ransom.

On October 22, Kordia chief information security officer Hilary Walton (who has since decamped to Microsoft) pointed cross the Tasman, where Australia’s privacy legislation allows for a fine of up to A$2.2m - and even possible jail time for executives involved - for a health data breach. New legislation raises the maximum fine to up to A$50m. The tightening follows major data breaches at Optus and health insurer Medibank.

Last week, the Privacy Commissioner said NZ should consider raising its current penalty of $10,000.

Webster’s predecessor, John Edwards, proposed $1m fines with a 2020 revamp of the Privacy Act, but the idea was knocked back by the Government.

The new Privacy Commissioner said last Tuesday: “I am certainly very interested in looking at the role that a financial penalty regime consistent with New Zealand consumer law could have, in terms of punishing people for poor management of people’s personal data.”

Webster added: “These regimes exist in many other jurisdictions.”

No mood for big moves

The Government has so far resisted change, however.

On making it illegal to pay a cyber ransom, Justice Minister Kiri Allan told the Herald: “While the Government understands making payments for cyber ransoms may be perceived as encouraging further attacks, taking criminal action against the victim raises issues of fairness in regard to making a victim a criminal when they are attempting to protect their business and livelihoods by making the payment.

“As such, there aren’t any current plans to criminalise those who pay cyber ransoms,” Allan added.

And on fines for firms that lose data to thieves because of poor levels of protection, Allan said: “Penalising those who fail to take sufficient steps to protect their data with substantial fines is not currently a priority for me as Justice Minister.”

Police and Crown cybersercurity agency Cert NZ advise against paying a cyber ransom, saying to do so incentivises and funds further offending, and provides not guarantee you’ll get your data back - or that it will not be used in a future extortion or blackmail attempt.

The Crown-based ID Care offers advice and support for anyone who thinks they are at risk of identity theft or fraud following an online scam or data breach.


Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Shares

Market close: Fletchers down 3.6%

24 Jun 05:46 AM
Premium
Business

Danone's NZ profits surge, dividend doubles to $19.8m

24 Jun 05:00 AM
Retail

Ikea to hire 500 staff for NZ launch, 100 more than planned

24 Jun 04:53 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Market close: Fletchers down 3.6%

Market close: Fletchers down 3.6%

24 Jun 05:46 AM

Oil prices suffered one of their steepest single-day falls in five years on Tuesday.

Premium
Danone's NZ profits surge, dividend doubles to $19.8m

Danone's NZ profits surge, dividend doubles to $19.8m

24 Jun 05:00 AM
Ikea to hire 500 staff for NZ launch, 100 more than planned

Ikea to hire 500 staff for NZ launch, 100 more than planned

24 Jun 04:53 AM
Major supermarket apologises for humiliating woman with false shoplifting claim

Major supermarket apologises for humiliating woman with false shoplifting claim

24 Jun 04:36 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP