Morpeth Pharmacy Listed by global Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Morpeth Pharmacy was listed by a global ransomware group on June 07, 2025, after internal files were exfiltrated in an attack. An undisclosed number of individuals may have been affected; anyone who has used the pharmacy is advised to check for further notices and monitor their personal information.
Ransomware groups continue to target healthcare providers of every size, treating even small community pharmacies as sources of sensitive operational and patient-related data. In this climate, a listing on a criminal leak site is often the first public signal that an organisation may have been compromised.
On 7 June 2025, Morpeth Pharmacy, also known as Wellway Pharmacy Limited, appeared on the leak site of the ransomware group that calls itself global. The group claims it exfiltrated internal files during a ransomware attack. The number of people affected remains unknown, and public detail about the precise scope of the incident is limited. For patients and staff connected to a local pharmacy, any such claim raises practical questions about the security of personal and medical information.
What happened
According to the available record, Morpeth Pharmacy was listed by the global ransomware group on or around 7 June 2025. The group asserts that it carried out a ransomware attack and exfiltrated internal files. No further technical details—such as the initial access method, the duration of any intrusion, the volume of data taken, or confirmation that systems were encrypted—have been disclosed in the public summary. The number of individuals potentially affected is listed as unknown. At present the listing itself constitutes an unverified claim by the threat actor rather than an independently confirmed breach report from the organisation or regulators.
Inside global
Global is one of several ransomware operations that maintain public leak sites to pressure victims. Like many such groups, it typically claims to have stolen data before or instead of encrypting systems, then posts the victim’s name and sample material to encourage payment. These groups commonly use phishing, compromised remote-access credentials, or unpatched software to gain entry, after which they move laterally, harvest credentials, and package files for exfiltration. Public reporting on global has described a pattern of opportunistic targeting across multiple sectors rather than exclusive focus on healthcare. Nothing in the present record indicates that global made additional statements specific to Morpeth Pharmacy beyond the listing and the assertion that internal files were taken.
About Morpeth Pharmacy
Morpeth Pharmacy operates as Wellway Pharmacy Limited, a private limited company established on 9 February 1995. It is located at The Surgery, Wellway, Morpeth, Northumberland, and provides standard community-pharmacy services: prescription dispensing, health consultations, and over-the-counter medications. Community pharmacies sit at the intersection of primary care and retail healthcare; they routinely handle patient identities, prescription histories, contact details, and sometimes payment or insurance information. Because they serve local populations and often share data with general practices and NHS systems, a compromise can affect both individual privacy and the continuity of everyday healthcare services.
The information in question
The only data category named in the public record is “internal files” said to have been exfiltrated in a ransomware attack. Exact contents have not been disclosed. Organisations of this type typically hold patient names and addresses, prescription records, dates of birth, contact telephone numbers or email addresses, staff employment details, and operational documents such as supplier invoices or internal correspondence. Whether any of those categories were among the files claimed by global remains unconfirmed. No file counts, sample documents, or specific data fields have been released in the available summary.
What's at stake
For individuals, the principal risks are identity misuse, targeted phishing that references genuine medical or contact details, and potential embarrassment or discrimination if sensitive health information becomes public. Even limited internal files can contain enough personal data to enable social-engineering attacks. For the pharmacy itself, consequences may include operational disruption, regulatory notification duties under UK data-protection law, reputational harm within a tight-knit community, and the cost of forensic investigation and system recovery. Because the scale of any exposure is unknown, both the organisation and its patients face a period of uncertainty until more definitive information emerges.
Were you affected?
If you have been a patient or employee of Morpeth Pharmacy, treat the listing as a prompt for caution rather than confirmed proof of compromise. Monitor bank and credit statements for unusual activity, be sceptical of unexpected emails or calls that reference the pharmacy or your prescriptions, and consider changing passwords that may have been reused across personal accounts. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. If you receive formal notification from the pharmacy or from the Information Commissioner’s Office, follow the specific advice provided in that communication.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Deakin Medical Listed by global Ransomware GroupAscot Vale Health Group Listed by global Ransomware GroupEpworth-Hospital Listed by global Ransomware Groupawmedicalvillage.org Listed by global Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Morpeth Pharmacy Listed by global Ransomware Group →
Publicly posted by global — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.