Ransomware group Orion claims attack on Morris Group International

A criminal gang has listed the British professional-services firm on its dark-web pressure site. The company has not confirmed anything, and the claim is unverified.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
A dark-themed computer screen displaying a minimalist dark-web marketplace interface with red warning symbols and profile listings, with keyboard and mouse in s
Share

Key points

  • Ransomware group Orion listed Morris Group International (morrisgroupint.com), a UK professional-services company, on its dark-web leak site, with the post dated 2025-10-28.
  • The listing was first spotted by threat-monitoring service Ransomware.live on 2026-08-05.
  • Morris Group International has not publicly confirmed any breach, and the claim could not be independently verified at the time of publication.
  • Leak-site listings are written by criminals to pressure companies into paying, and are sometimes exaggerated or entirely false.

A ransomware group calling itself Orion has named Morris Group International, a professional-services firm based in the United Kingdom, on its dark-web leak site. Leak sites are pages criminals run on hidden parts of the internet where they publicly name organisations they claim to have attacked, typically to push victims into paying a ransom.

The group's post is dated 2025-10-28. Ransomware.live, a monitoring service that tracks these criminal pages, flagged it on 2026-08-05. Gaps like that aren't unusual: monitoring services sometimes surface older posts well after the criminals first published them. Professional services firms have been a recurring target in campaigns we've tracked this year, including our June report on UNC3753's vishing and walk-in intrusions against legal and consulting firms.

Has Morris Group International confirmed a breach?

No. The company has made no public statement confirming an incident, and Threat Vectr could not independently verify the claim. That matters, because these listings are written by attackers whose goal is to cause maximum pressure on the named company. The listing may be exaggerated; it could be an outright fabrication.

None of that means the claim is false. The honest answer right now is: we don't know.

Should you worry if you're a customer or staff member?

The claim is unconfirmed, but a few steps are worth taking now.

Watch for phishing: criminals send fake emails pretending to be a trusted company to steal your login details or money. News of an alleged breach gives attackers a ready cover story, so any message claiming to be from Morris Group International about your account should be treated with immediate suspicion.

Don't reuse passwords. If the same password appears across multiple accounts and one service is ever genuinely breached, every other account sharing it becomes vulnerable. A free password manager fixes this quickly.

Be wary of unexpected calls. Scammers sometimes ring people after breach headlines, claiming to offer refunds or protective services. Hang up and call the company back on a number from its official website.

These steps don't require waiting for confirmation. They're good practice regardless of how this particular claim resolves.

© 2026 Threat Vectr