LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Morris Hospital Listed by royal Ransomware Group

HIGH severityUnverified claimHow we verify

Morris Hospital Listed by royal Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 22, 2023
Morris Hospital Listed by royal Ransomware Group

Reported May 22, 2023.

HIGH
Severity
May 22, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Morris Hospital Listed by royal Ransomware Group (reported May 22, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Morris Hospital was listed on the leak site of the royal ransomware group, according to reports dated May 22, 2023. The group claims to have stolen internal data from the organization in a ransomware attack that involved the exfiltration of internal files. The number of people affected remains unknown, and public detail on the incident is limited beyond the listing itself.

For a healthcare provider, any claim of data theft raises immediate questions about the confidentiality of operational and patient-related information. What is confirmed so far is the group's public assertion; independent verification of the full scope has not been detailed in available reporting.

Breaking down the breach

On or around May 22, 2023, Morris Hospital appeared on the royal ransomware group's leak site. The listing asserts that the group carried out a ransomware attack and exfiltrated internal files. No further technical specifics—such as the initial access method, the duration of unauthorized access, the precise volume of data taken, or any ransom demand—have been disclosed in the public record tied to this report.

The facts establish only that the hospital was named by the group and that the group claims theft of internal data. Counts of affected individuals are listed as unknown. No confirmation from Morris Hospital regarding the accuracy of the listing, the containment of any intrusion, or notifications to regulators or patients is included in the provided details. In short, the incident is known principally through the threat actor's claim rather than through a detailed public disclosure from the organization.

Who is royal?

Royal is a ransomware operation that became active in the public eye around mid-2022. Like many contemporary groups, it has typically relied on a double-extortion model: encrypting systems to disrupt operations while also copying data and threatening to publish it if payment is not made. The group has been observed targeting organizations across multiple sectors, including healthcare, manufacturing, and professional services, often after gaining access through compromised credentials, phishing, or exploited vulnerabilities.

Royal's leak site has served as the primary channel for naming victims and, in some cases, releasing samples or larger sets of stolen files. Public reporting on the group has described relatively professional negotiation tactics and a focus on high-impact targets whose downtime or data exposure could create pressure to pay. None of these general patterns constitute proof of the exact tactics used against Morris Hospital; they simply describe how the group has operated in documented cases. With respect to this incident, the sole specific claim is the leak-site listing itself and the assertion that internal data was stolen.

About Morris Hospital

Morris Hospital is a healthcare organization. Hospitals and similar providers routinely manage large volumes of sensitive information necessary for patient care, billing, staffing, and regulatory compliance. That typically includes medical records, insurance and payment details, contact information, and internal administrative files covering everything from supply chains to employee records.

A breach claim against any hospital is consequential because the sector operates under strict privacy expectations and legal obligations. Disruption of clinical systems can affect care delivery, while exposure of personal health information can create lasting privacy and financial risks for individuals. Even when the precise contents of a claimed theft remain unconfirmed, the mere assertion that a hospital's internal files have been taken warrants careful attention from patients, staff, and partners who may have shared data with the institution.

What was likely exposed

The available facts state that internal files were exfiltrated in a ransomware attack. No itemized list of data categories—such as patient names, Social Security numbers, clinical notes, financial records, or employee information—has been publicly detailed in connection with this listing. The number of people potentially affected is unknown.

Organizations of this type commonly hold protected health information, demographic and contact data, insurance details, and a range of business documents. It is reasonable to expect that internal files could encompass some mix of those materials, yet it would be inaccurate to treat any specific category as confirmed. Until Morris Hospital or a regulatory filing provides a clearer inventory, the exact contents of the claimed exfiltration remain unconfirmed. Readers should treat broad assumptions about what was taken as speculative.

Why it matters

For individuals who have received care at or worked with Morris Hospital, the primary concern is the possible misuse of personal or medical information. Exposed data can be used for identity theft, targeted phishing, insurance fraud, or other social-engineering attempts that reference real details to appear legitimate. Even internal administrative files can contain enough personal identifiers to create risk.

For the hospital itself, a ransomware incident—whether fully confirmed or still under assessment—can mean operational disruption, investigative and recovery costs, potential regulatory scrutiny, and erosion of trust among patients and partners. Because the scale and precise data types are undisclosed, the practical impact cannot yet be quantified. What can be said is that healthcare breaches often carry longer-tail consequences than breaches in less regulated sectors, simply because the information involved is both sensitive and enduringly useful to criminals.

No public facts establish negligence or specific security failures on the part of Morris Hospital; the record at this stage consists of the threat actor's claim. Attribution of blame without evidence would be inappropriate.

Were you affected?

If you have been a patient, employee, or business partner of Morris Hospital, consider practical steps. Monitor financial and insurance statements for unfamiliar activity. Be cautious of unexpected emails, calls, or messages that reference the hospital or personal details you may have shared with it; verify any such contact through official channels rather than replying directly. Place fraud alerts with major credit bureaus if you believe sensitive identifiers could be involved, and retain any breach notifications you later receive from the organization.

Because the number of people affected and the exact data taken remain unknown, there is no public list against which to check your name. You can run a free exposure scan of your email address to see whether it has already appeared in known breach datasets elsewhere; that check will not confirm or rule out involvement in this specific incident, but it can highlight whether your information is circulating more broadly and help you prioritize further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMorris Hospital security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Morris Hospital’s full breach history →

More recent breaches

Clarke County Hospital Listed by royal Ransomware GroupApril 14, 2023Corizon Healthcare Listed by royal Ransomware GroupMarch 30, 2023Graceworks Lutheran Services Listed by royal Ransomware GroupMarch 21, 2023Little Mountain Residential Care and Housing Society Listed by royal Ransomware GroupMarch 10, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Morris Hospital Listed by royal Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by royal — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram