MORTON WILLIAMS Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The MORTON WILLIAMS Listed by everest Ransomware Group (reported May 1, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to pressure organizations across retail and consumer sectors by combining network intrusion with data theft and public leak-site postings. In this environment, the appearance of MORTON WILLIAMS on a ransomware group's listing on May 1, 2024, fits a familiar pattern of claimed exfiltration followed by threats of release. Public detail remains limited to the group's assertions, yet the listing alone raises practical questions for anyone whose information may have been held by the company.
What is known is that the Everest ransomware group listed MORTON WILLIAMS and claimed to have taken internal files. No independent confirmation of the intrusion, the precise volume of data, or the number of people affected has been made available in the public record. The incident therefore stands as an unverified claim that still warrants careful attention from customers, employees, and partners.
Breaking down the breach
According to the available report, MORTON WILLIAMS was listed by the Everest ransomware group on May 1, 2024. The group stated that internal files had been exfiltrated during a ransomware attack and referenced a volume of 150 GB. Sample material was said to have been placed on public file-sharing services. The number of people affected is unknown, and no further technical details—such as the initial access method, the duration of the intrusion, or whether encryption was also deployed—have been disclosed. Because these elements come solely from the group's leak-site claim, they remain unverified. No official statement from the company confirming or denying the listing has been incorporated into the public facts surrounding the report.
The group behind it: everest
Everest is a ransomware operation that follows the double-extortion model now common among such groups. After gaining access to a victim network, operators typically steal data before or alongside any encryption, then list the organization on a dedicated leak site if payment demands are not met. The group has previously claimed responsibility for attacks on a range of businesses and has used public file-hosting services to distribute samples as proof of theft. Listings are presented as facts by the actors themselves; outside verification is often incomplete or absent. In the present case, the only specific assertions about MORTON WILLIAMS are those contained in the May 1, 2024 listing: that internal files were taken and that roughly 150 GB of material was involved. No additional statements uniquely tied to this victim beyond that listing appear in the reported facts.
About MORTON WILLIAMS
MORTON WILLIAMS operates as a supermarket chain serving primarily the New York metropolitan area. Businesses of this type maintain stores that handle everyday grocery sales, loyalty programs, supplier contracts, and workforce management. They routinely process payment information, customer contact details, employee records, inventory systems, and internal operational documents. A claimed breach at such an organization is consequential because the data held can include both personal identifiers of shoppers and staff and commercially sensitive material that, if released, could affect day-to-day operations or expose individuals to secondary risks. The company's public website is associated with the listing, but no further corporate disclosures form part of the reported facts.
What data was at risk
The facts identify the exposed material only as "internal files exfiltrated in ransomware attack," with the group claiming a total of 150 GB. Exact file types, whether customer records, employee data, financial documents, or other categories were included, and the number of individuals whose information may appear remain undisclosed. Organizations in the grocery retail sector typically store names, addresses, purchase histories, payment-related details, payroll information, and vendor contracts. Because none of these categories has been confirmed as present in the claimed dump, any assumption about specific contents would be speculative. The public record simply does not establish what, if anything, was taken beyond the group's general description of internal files.
Why it matters
For individuals, the primary concern is the possibility that personal or financial details could later surface and be misused for fraud, phishing, or identity-related crime. Even when the precise data set is unknown, the mere claim of exfiltration creates a period of elevated risk that lasts until the material is either secured or proven not to contain sensitive records. For the organization, a public listing can disrupt supplier relationships, invite regulatory scrutiny, and require internal investigation and notification efforts, regardless of whether the full claim is later substantiated. In both cases the consequences are practical rather than abstract: monitoring accounts, reviewing communications, and preparing for potential follow-on activity become necessary steps while the facts remain incomplete.
If your data was in this claimed breach
Begin by treating any unsolicited messages that reference the incident with caution, as criminals often exploit news of breaches to launch phishing campaigns. Review bank and credit-card statements for unfamiliar charges, enable multi-factor authentication on important accounts, and consider placing a fraud alert with the major credit bureaus if you have reason to believe your information was held by the company. Change passwords that may have been reused across services. Because the exact contents of the claimed files are unconfirmed, these measures remain precautionary. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a scan provides an additional, independent signal of past exposure and can help prioritize further protective actions.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Broward Realty Corp Listed by everest Ransomware GroupSpeed Advisory Listed by everest Ransomware GroupThe Law Office of Omar O. Vargas, P.C. Listed by everest Ransomware GroupCukierski & Associates, LLC Listed by everest Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the MORTON WILLIAMS Listed by everest Ransomware Group →
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.