LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › morrisgroupint.com Listed by lockbit3 Ransomware Group

HIGH severityUnverified claimHow we verify

morrisgroupint.com Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 14, 2024
morrisgroupint.com Listed by lockbit3 Ransomware Group

Reported May 14, 2024.

HIGH
Severity
May 14, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The morrisgroupint.com Listed by lockbit3 Ransomware Group (reported May 14, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or professional details may sit inside Morris Group International’s systems now face a concrete uncertainty: whether those records were among the internal files a ransomware group claims to have taken. When a company that designs and supplies plumbing, drainage and related equipment across dozens of sites is listed on a criminal leak site, the practical stakes are immediate—identity fraud, targeted phishing, or exposure of business contacts that can be used against individuals and partners alike. Public detail remains limited, yet the listing itself is enough to warrant careful attention from anyone who has dealt with the organisation.

On 14 May 2024, the domain morrisgroupint.com appeared on a site operated by the ransomware group known as lockbit3. The group asserts that it exfiltrated internal files during a ransomware attack. No independent confirmation of the volume of data, the exact systems involved, or the number of people affected has been published, and the company has not been reported as having issued a detailed public statement at the time of writing.

Breaking down the breach

What is known rests almost entirely on the lockbit3 listing. The group claims that internal files belonging to Morris Group International were stolen as part of a ransomware operation. The date associated with the public report is 14 May 2024. No figure for the number of people affected has been disclosed, and the precise method of initial access—whether phishing, an unpatched vulnerability, compromised credentials or another vector—has not been made public. Likewise, there is no confirmed information about whether encryption was successfully deployed, whether a ransom demand was issued, or whether any negotiation took place. In short, the incident is documented only at the level of a leak-site claim of data exfiltration; further technical or operational specifics remain undisclosed.

Because the only concrete assertion is that “internal files” were taken, it is not possible to state with certainty which business units, which geographic locations, or which categories of records were involved. Organisations of this size routinely maintain a mixture of operational, commercial and personnel data; without a verified inventory, any assessment of scope stays provisional.

The group behind it: lockbit3

Lockbit3 is a well-documented ransomware operation that has been active for several years under successive versions of the LockBit brand. The group typically operates a ransomware-as-a-service model, supplying affiliates with malware and infrastructure in exchange for a share of any ransom payments. Its hallmark tactic is double extortion: after encrypting systems, operators also exfiltrate data and threaten to publish it on a dedicated leak site if the victim does not pay. Listings on that site are therefore claims by the group itself; they are not independent forensic findings.

Public reporting over time has shown LockBit affiliates targeting a wide range of sectors, including manufacturing, professional services and critical infrastructure suppliers. The group has historically used high-pressure deadlines, sample data dumps and, on occasion, auction-style postings to increase leverage. None of those broader patterns, however, constitute proof of the specific contents or volume of material allegedly taken from Morris Group International; they simply describe how the actor is known to behave in other cases.

About morrisgroupint.com

Morris Group International describes itself as a collection of 28 divisions and partnerships operating from 27 locations worldwide. Its product range covers stainless-steel sanitary ware, engineered plumbing and drainage systems, vacuum plumbing, drinking fountains and electric water heaters, among other specialised building-services equipment. Companies in this sector typically hold supplier and customer contracts, engineering drawings, quality-control records, employee information, and commercial correspondence with architects, contractors and public-sector buyers.

A breach at such an organisation is consequential because the data it holds can link individuals—employees, sales contacts, project managers—to specific commercial relationships and physical sites. Even if the primary business is industrial rather than consumer-facing, the internal files of a multi-location manufacturer often contain enough personally identifiable information and sensitive commercial detail to create lasting risk for the people named in them.

What was likely exposed

The only data type named in the available record is “internal files exfiltrated in a ransomware attack.” No inventory of those files has been published, and the number of people affected remains unknown. Organisations that manufacture and distribute specialised plumbing and building products commonly store employee directories, payroll or human-resources records, customer and supplier contact lists, project specifications, invoices, and internal communications. It is therefore reasonable to expect that some combination of those categories could be present among the material the group claims to hold. At the same time, it is essential to state plainly that the exact contents are unconfirmed; no public source has verified which specific documents or data fields were taken.

Why it matters

For individuals whose details may appear in the stolen files, the principal risks are identity-related fraud, spear-phishing that leverages accurate personal or professional context, and the long-term recirculation of contact information on criminal markets. Even limited internal documents can supply enough authentic detail to make subsequent social-engineering attempts more convincing. For the organisation itself, the consequences include potential regulatory notification duties, contractual obligations to customers and partners, reputational damage, and the operational cost of investigating and remediating the intrusion. Because the scale of the alleged exfiltration is undisclosed, both the personal and institutional impact remain difficult to quantify, yet the mere existence of a credible claim is sufficient to justify precautionary measures.

Were you affected?

If you have ever worked for, contracted with, or supplied Morris Group International or any of its divisions, treat the possibility of exposure seriously. Monitor financial and email accounts for unusual activity, enable multi-factor authentication wherever it is available, and be sceptical of unsolicited messages that reference the company or its projects. Consider placing fraud alerts with credit-reporting agencies if you believe sensitive personal data may have been involved. As a practical next step, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; doing so provides an early indication of whether your information is circulating beyond this single incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companymorrisgroupint.com security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See morrisgroupint.com’s full breach history →

More recent breaches

tsebrakes.com Listed by lockbit3 Ransomware GroupDecember 23, 2024marmon-herrington.com Listed by lockbit3 Ransomware GroupDecember 13, 2024sullivansteelservice.com Listed by lockbit3 Ransomware GroupAugust 11, 2024piedmonthoist.com Listed by lockbit3 Ransomware GroupJuly 17, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the morrisgroupint.com Listed by lockbit3 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram