LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › DZL Listed by morpheus Ransomware Group

HIGH severityUnverified claimHow we verify

DZL Listed by morpheus Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 24, 2025
DZL Listed by morpheus Ransomware Group

Reported February 24, 2025.

HIGH
Severity
February 24, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

DZL was listed by the morpheus ransomware group on 24 February 2025, with internal files reported as exfiltrated in the attack. An undisclosed number of people may have been affected; readers should check any official statements from DZL and follow guidance on monitoring accounts and changing credentials.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target software vendors whose platforms sit at the centre of everyday institutional work, turning internal systems into leverage for extortion. On 24 February 2025 the group known as morpheus listed DZL, a global provider of library-management software, among its claimed victims. Public detail remains limited: the number of people affected is unknown, and the only description of the material involved is that internal files were allegedly exfiltrated during a ransomware attack. Even so, the listing places a company whose products support academic, public and corporate libraries worldwide under the same pressure that has become routine across the technology sector.

Because library-management platforms often hold operational records, user data and administrative credentials, any confirmed compromise can ripple outward to the institutions that rely on them. At present the claim rests solely on the group’s leak-site entry; independent verification has not been published.

Breaking down the breach

According to the available record, DZL was listed by the morpheus ransomware group on 24 February 2025. The sole technical detail supplied is that internal files were allegedly exfiltrated in the course of a ransomware attack. No figure has been given for the volume of data taken, no timeline of the intrusion has been released, and the number of individuals whose information may have been involved remains unknown. The method of initial access, the duration of the attackers’ presence, and whether encryption of production systems occurred are all undisclosed. The listing itself constitutes the group’s claim that it holds DZL material and is prepared to publish or sell it; that claim has not been independently confirmed in the public reporting available to date.

Who is morpheus?

Morpheus is a ransomware operation that follows the now-familiar double-extortion model: data are stolen before systems are encrypted, and victims are threatened with public release if a ransom is not paid. The group maintains a dark-web leak site on which it posts victim names, sample files and countdown timers. Like other actors in this space, it typically seeks organisations whose data carry operational or reputational value, then uses the threat of disclosure to increase pressure. Public reporting has documented similar listings against software and service providers in multiple sectors; the group’s communications are usually terse and focused on the volume or sensitivity of the material it claims to possess. In the present case the only statement attributable to morpheus is the listing of DZL itself; no further statements specific to this victim have been made public.

About DZL

DZL is a global software company that develops library-management solutions. Its principal products, known as Liberty and Eclipse, are used by academic, public and corporate libraries and information centres to handle cataloguing, circulation, digital-resource acquisition and day-to-day administration. Organisations of this type sit at the intersection of cultural institutions, universities and private information centres; their software routinely processes records of holdings, borrower activity, staff accounts and system configurations. A breach affecting such a vendor therefore has the potential to reach not only the company’s own employees and contractors but also the libraries and end-users who depend on its platforms. The consequential nature of the incident stems from that reach: even limited internal files can contain credentials, configuration data or customer-related records that, if misused, affect multiple institutions at once.

What data was at risk

The only data type named in the public record is “internal files” said to have been exfiltrated during the ransomware attack. No inventory of those files, no classification of their sensitivity, and no confirmation of whether customer or end-user data were included has been released. Organisations that supply library-management software typically hold source code or configuration repositories, employee and contractor records, customer contact lists, support tickets, and sometimes aggregated usage statistics or authentication tokens. Whether any of those categories were present among the files claimed by morpheus is unconfirmed. Until DZL or independent investigators publish a fuller accounting, the precise contents remain unknown and should not be assumed.

What's at stake

For individuals whose information may have been among the internal files, the practical risks include targeted phishing that references genuine organisational details, credential stuffing if passwords or tokens were stored, and, in rarer cases, identity-related fraud if personal data were present. For the libraries and information centres that use DZL products, the concern is secondary exposure: compromised vendor credentials or configuration data could be used to probe their own systems. For DZL itself the stakes are operational continuity, customer trust and the cost of forensic investigation and remediation. Because the scale of the exfiltration and the exact nature of the files remain undisclosed, these risks cannot yet be quantified; they are real possibilities rather than established outcomes.

What to do if you're exposed

Anyone who has worked with or held an account related to DZL systems should treat the listing as a prompt for basic hygiene rather than proof of personal compromise. Change passwords on any accounts that may have been shared with or managed through the company, enable multi-factor authentication where it is available, and watch for unexpected login alerts or phishing messages that reference library or software-support themes. Monitor financial and credit activity if personal identifiers could plausibly have been stored. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a scan does not confirm involvement in this incident but provides a practical starting point for personal risk assessment. If DZL issues official guidance or a notification, follow those instructions promptly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyDZL security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See DZL’s full breach history →

More recent breaches

LYNXSPA Listed by morpheus Ransomware GroupJanuary 17, 20253I INFOTECH Listed by morpheus Ransomware GroupJune 8, 2026VALLEREDONDO Listed by morpheus Ransomware GroupDecember 27, 2025SCIPIONI Listed by morpheus Ransomware GroupDecember 12, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the DZL Listed by morpheus Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by morpheus — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram