Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

NZ Insurance Targeted in Ransomware Attack

March 13, 2025
Reading Time: 3 mins read
in Incidents

New Zealand insurance company Vercoe Insurance Brokers has fallen victim to a cyberattack orchestrated by the DragonForce ransomware gang. The cybercriminals claim to have exfiltrated over 60 gigabytes of sensitive data, putting the company and its clients at significant risk. While Vercoe has confirmed it is investigating the attack and has restored its systems, the looming threat of data exposure remains. This incident underscores the growing cybersecurity challenges facing businesses worldwide, particularly in the financial and insurance sectors.

DragonForce’s Attack and ThreatsDragonForce, a notorious ransomware group, listed Vercoe as a victim on its darknet leak site on March 5, 2025. The gang alleges it successfully extracted 60.67 gigabytes of data but has yet to release any documents proving the breach. At the time of writing, the attackers have issued a four-day ultimatum, threatening to publish the stolen data if their undisclosed ransom demands are not met.

The attack follows a familiar pattern employed by DragonForce and similar ransomware groups. Known for using double-extortion tactics, DragonForce locks victims out of their systems while simultaneously threatening to release sensitive data unless a ransom is paid. Their aggressive strategies and ransomware-as-a-service model have made them a formidable threat in the cybercrime landscape.

Vercoe’s Response and InvestigationVercoe Insurance Brokers has confirmed that it is actively investigating the claims made by the hackers.

A spokesperson for the company told Cyber Daily that Vercoe has engaged external cybersecurity experts to assess the full scope of the breach, restore affected systems, and strengthen its IT security measures.

“Since the compromise, we have engaged external experts to restore the systems that were out of operation, investigate the full scope and nature of any malicious activity, and review our IT security,” Vercoe said in a statement. “We have restored access to all systems and are back to full operational capacity. Thankfully, it appears that the impact on our ability to conduct our day-to-day work for our clients has been limited.

“We are grateful to our external providers for working hard to get us to this point.”

As a precautionary measure, Vercoe has reported the incident to New Zealand’s Office of the Privacy Commissioner and the Financial Markets Authority. Additionally, the brokerage has informed key stakeholders and insurer clients about the potential risks. The company has pledged to notify affected parties should personal data be confirmed as compromised.

Who is DragonForce?
DragonForce is currently ranked as the 34th most active ransomware group in the world. Since its emergence in December 2023, the group has claimed responsibility for attacks on at least 140 organizations across various industries. Although some analysts have speculated that DragonForce may have ties to Malaysian hacktivist group DragonForce Malaysia due to the name similarity, no concrete evidence has established a link between the two entities.

The gang is suspected of having connections to the infamous LockBit ransomware operation, one of the most disruptive ransomware groups globally. DragonForce operates on a ransomware-as-a-service (RaaS) model, allowing cybercriminal affiliates to carry out attacks while receiving a substantial share of ransom payments. Notably, the gang offers up to an 80% commission to its affiliates, an unusually high percentage that incentivizes widespread attacks.

DragonForce primarily advertises its services on Russian-language hacking forums, targeting organizations with weak cybersecurity defenses. Its recent victims in the ANZ region include Tristram European, a New Zealand car dealership that appeared on the group’s leak site on February 21, 2025.

Reference:

  • NZ Brokerage Vercoe Insurance Targeted in DragonForce Ransomware Attack
Tags: cyber incidentsCyber Incidents 2025Cyber threatsMarch 2025
ADVERTISEMENT

Related Posts

Sompo Data Breach Puts 17.5M Records At Risk

Sompo Data Breach Puts 17.5M Records At Risk

June 11, 2025
BHA Hit By Ransomware But Races Continue

BHA Hit By Ransomware But Races Continue

June 11, 2025
DDoS Disrupts Roularta Media In Belgium

DDoS Disrupts Roularta Media In Belgium

June 11, 2025
Illinois HFS Employee Phishing Leaks Data

Texas DOT Breach Leaks 300K Crash Reports

June 10, 2025
Illinois HFS Employee Phishing Leaks Data

Cyberattack Disrupts UNFI Food Deliveries

June 10, 2025
Illinois HFS Employee Phishing Leaks Data

Illinois HFS Employee Phishing Leaks Data

June 10, 2025

Latest Alerts

Fake Sora AI Lure Installs Infostealer

FIN6 Uses Fake Resumes To Hack Recruiters

Microsoft Fixes Exploited WebDAV Zero Day

Google Bug Exposed Any User’s Phone Number

Roundcube RCE Flaw Risks 84,000 Servers

New Skitnet Malware Arms Ransomware Gangs

Subscribe to our newsletter

    Latest Incidents

    BHA Hit By Ransomware But Races Continue

    Sompo Data Breach Puts 17.5M Records At Risk

    DDoS Disrupts Roularta Media In Belgium

    Texas DOT Breach Leaks 300K Crash Reports

    Illinois HFS Employee Phishing Leaks Data

    Cyberattack Disrupts UNFI Food Deliveries

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial