DZL Listed by morpheus Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
DZL was listed by the morpheus ransomware group on 24 February 2025, with internal files reported as exfiltrated in the attack. An undisclosed number of people may have been affected; readers should check any official statements from DZL and follow guidance on monitoring accounts and changing credentials.
Ransomware groups continue to target software vendors whose platforms sit at the centre of everyday institutional work, turning internal systems into leverage for extortion. On 24 February 2025 the group known as morpheus listed DZL, a global provider of library-management software, among its claimed victims. Public detail remains limited: the number of people affected is unknown, and the only description of the material involved is that internal files were allegedly exfiltrated during a ransomware attack. Even so, the listing places a company whose products support academic, public and corporate libraries worldwide under the same pressure that has become routine across the technology sector.
Because library-management platforms often hold operational records, user data and administrative credentials, any confirmed compromise can ripple outward to the institutions that rely on them. At present the claim rests solely on the group’s leak-site entry; independent verification has not been published.
Breaking down the breach
According to the available record, DZL was listed by the morpheus ransomware group on 24 February 2025. The sole technical detail supplied is that internal files were allegedly exfiltrated in the course of a ransomware attack. No figure has been given for the volume of data taken, no timeline of the intrusion has been released, and the number of individuals whose information may have been involved remains unknown. The method of initial access, the duration of the attackers’ presence, and whether encryption of production systems occurred are all undisclosed. The listing itself constitutes the group’s claim that it holds DZL material and is prepared to publish or sell it; that claim has not been independently confirmed in the public reporting available to date.
Who is morpheus?
Morpheus is a ransomware operation that follows the now-familiar double-extortion model: data are stolen before systems are encrypted, and victims are threatened with public release if a ransom is not paid. The group maintains a dark-web leak site on which it posts victim names, sample files and countdown timers. Like other actors in this space, it typically seeks organisations whose data carry operational or reputational value, then uses the threat of disclosure to increase pressure. Public reporting has documented similar listings against software and service providers in multiple sectors; the group’s communications are usually terse and focused on the volume or sensitivity of the material it claims to possess. In the present case the only statement attributable to morpheus is the listing of DZL itself; no further statements specific to this victim have been made public.
About DZL
DZL is a global software company that develops library-management solutions. Its principal products, known as Liberty and Eclipse, are used by academic, public and corporate libraries and information centres to handle cataloguing, circulation, digital-resource acquisition and day-to-day administration. Organisations of this type sit at the intersection of cultural institutions, universities and private information centres; their software routinely processes records of holdings, borrower activity, staff accounts and system configurations. A breach affecting such a vendor therefore has the potential to reach not only the company’s own employees and contractors but also the libraries and end-users who depend on its platforms. The consequential nature of the incident stems from that reach: even limited internal files can contain credentials, configuration data or customer-related records that, if misused, affect multiple institutions at once.
What data was at risk
The only data type named in the public record is “internal files” said to have been exfiltrated during the ransomware attack. No inventory of those files, no classification of their sensitivity, and no confirmation of whether customer or end-user data were included has been released. Organisations that supply library-management software typically hold source code or configuration repositories, employee and contractor records, customer contact lists, support tickets, and sometimes aggregated usage statistics or authentication tokens. Whether any of those categories were present among the files claimed by morpheus is unconfirmed. Until DZL or independent investigators publish a fuller accounting, the precise contents remain unknown and should not be assumed.
What's at stake
For individuals whose information may have been among the internal files, the practical risks include targeted phishing that references genuine organisational details, credential stuffing if passwords or tokens were stored, and, in rarer cases, identity-related fraud if personal data were present. For the libraries and information centres that use DZL products, the concern is secondary exposure: compromised vendor credentials or configuration data could be used to probe their own systems. For DZL itself the stakes are operational continuity, customer trust and the cost of forensic investigation and remediation. Because the scale of the exfiltration and the exact nature of the files remain undisclosed, these risks cannot yet be quantified; they are real possibilities rather than established outcomes.
What to do if you're exposed
Anyone who has worked with or held an account related to DZL systems should treat the listing as a prompt for basic hygiene rather than proof of personal compromise. Change passwords on any accounts that may have been shared with or managed through the company, enable multi-factor authentication where it is available, and watch for unexpected login alerts or phishing messages that reference library or software-support themes. Monitor financial and credit activity if personal identifiers could plausibly have been stored. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a scan does not confirm involvement in this incident but provides a practical starting point for personal risk assessment. If DZL issues official guidance or a notification, follow those instructions promptly.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
LYNXSPA Listed by morpheus Ransomware Group3I INFOTECH Listed by morpheus Ransomware GroupVALLEREDONDO Listed by morpheus Ransomware GroupSCIPIONI Listed by morpheus Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the DZL Listed by morpheus Ransomware Group →
Publicly posted by morpheus — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.