Microworks Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Microworks was listed by the Rhysida ransomware group on October 15, 2024, after internal files were exfiltrated in a ransomware attack. Individuals who may have had dealings with the organization should review their accounts and change any credentials that might have been exposed.
On October 15, 2024, the ransomware group known as rhysida listed Microworks on its leak site, claiming the company had been hit by a ransomware attack that involved the exfiltration of internal files. The number of people affected remains unknown, and public detail on the incident is limited to this listing and the description of the data as internal files taken during the attack.
Microworks develops point-of-sale systems used in pizza delivery, restaurant management, and franchise food service. A breach involving a provider of such systems raises questions about the security of operational data that restaurants and related businesses rely on, even though the precise scope and contents of any stolen material have not been independently confirmed.
What happened
According to the available record, Microworks was listed by the rhysida ransomware group on October 15, 2024. The group claims that internal files were exfiltrated as part of a ransomware attack. No further public information has been released about the timing of the intrusion, the method of access, the volume of data taken, or whether any ransom demand was made or paid. The number of individuals potentially affected is listed as unknown. Beyond the leak-site claim itself, independent verification of the incident details has not been published.
The group behind it: rhysida
Rhysida is a ransomware operation that became publicly active in 2023. The group typically follows a double-extortion model: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. Rhysida has previously claimed responsibility for attacks across multiple sectors, including healthcare, education, government, and private industry. Its operators often use standard ransomware techniques such as phishing or exploitation of unpatched remote-access services to gain initial footholds, then move laterally to identify and extract valuable files before deploying encryption. Listings on the group's site are claims made by the actors themselves; they do not constitute independent confirmation that every detail of an attack occurred exactly as described.
In this case, the facts state only that Microworks was listed and that internal files were said to have been exfiltrated. No additional statements attributed specifically to rhysida about this victim appear in the public record provided.
Who is Microworks?
Microworks is a technology company that supplies point-of-sale software under the name Prism, marketed as a computer system suited to pizza delivery operations, restaurant management, and franchise food-service businesses. Organisations of this type typically handle customer order data, payment processing interfaces, inventory records, employee scheduling information, and franchise-level operational metrics. Because these systems sit at the centre of daily restaurant operations, a compromise can affect both the software provider and the restaurants that depend on it. Public detail does not describe Microworks' internal size, customer base, or security posture; the consequence of a breach lies in the potential exposure of business and customer-related information that such platforms commonly process.
What data was at risk
The facts name the exposed material only as "internal files exfiltrated in ransomware attack." No further breakdown of file types, categories of personal data, or volume has been disclosed. Companies that develop and support restaurant point-of-sale systems ordinarily store or process customer contact details, order histories, payment-related metadata, employee records, and proprietary business documents. Whether any of those categories were present among the files claimed by rhysida remains unconfirmed. Exact contents of the exfiltrated material are therefore unknown.
What's at stake
For individuals whose information may have been among the internal files, the practical risks include possible misuse of contact details or other personal data for phishing or identity-related fraud. For restaurants and franchise operators that rely on Microworks systems, the concern centres on operational disruption, potential leakage of business records, and the need to verify that their own customer and employee data were not included. The organisation itself faces reputational and operational costs associated with investigating the claim, notifying affected parties if required, and restoring confidence in its platform. Because the number of people affected is unknown and the precise data types remain undisclosed, the full extent of these risks cannot yet be quantified.
If your data was in this claimed breach
Public confirmation that any specific individual's data was taken has not been issued. If you are a customer, employee, or partner of Microworks or of a restaurant that uses its Prism point-of-sale system, the following practical steps are advisable:
- Monitor financial accounts and credit reports for unexpected activity.
- Treat unsolicited emails or calls requesting personal or payment information with caution, as they may be phishing attempts that reference the incident.
- Change passwords on any accounts that may have shared credentials with systems connected to Microworks services, and enable multi-factor authentication where available.
- Retain any official notifications you receive from Microworks or from restaurants that use its software, and follow the guidance they provide.
Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. This does not confirm or rule out involvement in the Microworks incident, but it can surface other exposures that warrant attention.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Goodwill North Central Texas Listed by rhysida Ransomware GroupEngedi Listed by rhysida Ransomware GroupThe Washington Times Listed by rhysida Ransomware GroupEl Debate Listed by rhysida Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Microworks Listed by rhysida Ransomware Group →
Publicly posted by rhysida — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.