morricetransportation.com Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
morricetransportation.com has been listed by the safepay ransomware group, with internal files reported as exfiltrated; the disclosure occurred on April 04, 2025, while the actual date of the intrusion has not been established. An undisclosed number of people may be affected, so individuals are advised to check whether their information appears in the published files and to monitor their accounts for unusual activity.
Ransomware groups continue to target mid-sized logistics and transportation firms across North America, exploiting the sector’s reliance on interconnected systems and the high operational cost of downtime. In this environment, the appearance of a company name on a ransomware leak site often serves as the first public signal that data may have been taken and that pressure is being applied.
On 4 April 2025, the ransomware group known as safepay listed morricetransportation.com among its claimed victims. Public reporting indicates that internal files were exfiltrated as part of a ransomware attack. The number of people affected remains unknown, and many operational details have not been disclosed. The listing itself is a claim by the group; independent confirmation of the full scope has not been made public.
Breaking down the breach
According to available information, morricetransportation.com was listed by the safepay ransomware group on 4 April 2025. The reported summary states that internal files were exfiltrated during a ransomware attack. No public figures have been released for the volume of data taken, the precise date of initial access, the method of intrusion, or the number of individuals whose information may have been involved. The scale of any encryption or disruption to operations is likewise undisclosed. What is known rests on the group’s leak-site claim and the accompanying description of file exfiltration; further technical or forensic detail has not entered the public record.
The group behind it: safepay
Safepay is a ransomware operation that follows the now-common double-extortion model: data is stolen before systems are encrypted, and the threat of public release is used to pressure victims into paying. Groups of this type typically maintain dedicated leak sites where they post victim names, sample files, and countdowns. They often target organisations whose operations cannot easily tolerate prolonged outages, including logistics and transportation companies. Prior public activity by safepay has followed this pattern of listing victims and claiming data theft, though each incident must be assessed on its own evidence. In the present case, the group claims to have obtained internal files from morricetransportation.com; that claim has not been independently verified in the material available here.
morricetransportation.com and its sector
Morrice Transportation is a logistics and transportation company based in Windsor, Ontario, Canada. It provides ground freight services across North America, including cross-border shipping, expedited deliveries, and hazardous-materials hauling. The company operates a fleet of more than 300 pieces of equipment. Firms in this sector routinely handle shipment records, customer and partner contact details, driver and employee information, vehicle and route data, and documentation related to regulated cargo. A breach affecting such an organisation can therefore touch both commercial operations and the personal data of employees, contractors, and business customers who rely on reliable freight movement.
The information in question
Public reporting names the exposed material only as “internal files exfiltrated in a ransomware attack.” No further breakdown of file types, databases, or categories of personal information has been disclosed. Organisations of this kind typically hold employee records, customer and shipper details, invoices, contracts, route and fleet data, and compliance documentation for hazardous materials. Whether any of those categories were among the files taken remains unconfirmed. The exact contents of the exfiltrated material are therefore unknown at this time.
Why it matters
For individuals whose data may have been included, the practical risks include potential misuse of contact or identity details, targeted phishing that references real shipments or employment, and longer-term exposure if the material is later sold or redistributed. For the organisation, the consequences can include operational disruption, regulatory notification obligations, contractual issues with customers, and reputational harm—especially when hazardous-materials or cross-border work is involved. Because the number of affected people and the precise data types remain unknown, the full extent of personal impact cannot yet be measured. The listing by a ransomware group nonetheless signals that sensitive internal material may now be outside the company’s control.
What to do if you're exposed
If you have a past or present relationship with Morrice Transportation—as an employee, contractor, customer, or partner—treat the possibility of exposure seriously even while details remain limited. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and be alert to phishing messages that reference freight, invoices, or employment. Consider placing fraud alerts with credit bureaus if personal identifiers may have been involved. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Official updates from the company or relevant authorities should be followed as they become available; until then, caution and basic hygiene remain the most practical first steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
larosadelmonte.com Listed by safepay Ransomware Grouppuertoricowarehousing.com Listed by safepay Ransomware Grouphennertanklines.com Listed by safepay Ransomware Groupultimateclasslimo.com Listed by safepay Ransomware GroupLatest breaches
Publicly posted by safepay — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.