CSIDB logo
Incident

Mercury IT

Incident posture

Attack window
Nov 2022
Location
New Zealand
Status
Historical
CIA posture
Available to members
Updated
2025-10-15 00:00

Linked entities

Victim
Mercury IT
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Nov 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyber incident impacted Mercury IT, a managed service provider, compromising systems and affecting downstream customer operations. Personal information was exposed, prompting involvement from national cybersecurity authorities and the Privacy Commissioner to address the breach and support affected organizations. The response emphasized mitigating risks, securing data, and ensuring timely notifications to individuals whose sensitive details were potentially accessed.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On November 30, 2022, New Zealand’s National Cyber Security Centre (NCSC) publicly acknowledged an ongoing cybersecurity incident affecting Mercury IT, a managed service provider (MSP). The NCSC initiated a coordinated response effort, working directly with Mercury IT and other relevant agencies to assess the scope and severity of the breach. Organizations utilizing Mercury IT’s services were advised to immediately review their systems for indicators of unauthorized access or anomalous activity, suggesting potential compromise of client networks through the MSP’s infrastructure. The NCSC emphasized the incident’s significance due to the inherent risks posed by MSP breaches, which can cascade across multiple downstream customers. Impact assessments remained ongoing at the time of the announcement, with no definitive public confirmation of the specific attacker methodologies, data exfiltrated, or total number of affected entities.

The Office of the Privacy Commissioner concurrently issued guidance underscoring the incident’s potential implications for personal information security. Organizations relying on Mercury IT were urged to proactively audit their data holdings to identify any compromised personal data, adhering to mandatory breach reporting obligations under New Zealand’s Privacy Act if thresholds were met. This guidance highlighted the necessity for robust incident response plans, particularly for third-party service provider compromises. The NCSC maintained its advisory role, offering direct support to Mercury IT’s affected customers while continuing its investigation alongside the MSP. No further details regarding containment measures, restoration timelines, or attribution were disclosed publicly as the incident response progressed.

Sources

Sources available to members: 2 sources.

CSIDB