Ransomware group Orion claims attack on Morris Group International
A criminal gang has listed the British professional-services firm on its dark-web pressure site. The company has not confirmed anything, and the claim is unverified.

Key points
- Ransomware group Orion listed Morris Group International (morrisgroupint.com), a UK professional-services company, on its dark-web leak site, with the post dated 2025-10-28.
- The listing was first spotted by threat-monitoring service Ransomware.live on 2026-08-05.
- Morris Group International has not publicly confirmed any breach, and the claim could not be independently verified at the time of publication.
- Leak-site listings are written by criminals to pressure companies into paying, and are sometimes exaggerated or entirely false.
A ransomware group calling itself Orion has named Morris Group International, a professional-services firm based in the United Kingdom, on its dark-web leak site. Leak sites are pages criminals run in hidden corners of the internet where they publicly name organisations they claim to have attacked, hoping the embarrassment and threat of data release will push victims into paying a ransom.
The listing, dated 2025-10-28, was flagged by Ransomware.live, a service that monitors these criminal pages, on 2026-08-05. The gap between those two dates is not unusual. Monitoring services sometimes detect older posts well after the criminals first published them.
Has Morris Group International confirmed a breach?
No. Morris Group International has made no public statement confirming an incident, and Threat Vectr could not independently verify the claim. That matters, because these listings are written by attackers whose goal is to cause maximum pressure on the named company. They are sometimes exaggerated. They are occasionally outright fabrications.
None of that means the claim is false. It means the honest answer right now is: we do not know.
What should customers or staff do in the meantime?
While the claim is unconfirmed, a few sensible steps are worth taking now rather than later.
Watch for phishing, which is where criminals send fake emails pretending to be a trusted company in order to steal your login details or money. News of an alleged breach gives attackers a convincing cover story: an email claiming to be from Morris Group International about "your account" or "breach compensation" should be treated with immediate suspicion.
Do not reuse passwords. If you use the same password across multiple accounts and one service is ever genuinely breached, every other account sharing that password becomes vulnerable. A free password manager makes this easy to fix.
Be wary of unexpected phone calls. Scammers sometimes ring people in the wake of breach headlines, claiming to offer refunds or protective services. Hang up and call the company back on a number you find yourself from their official website.
None of these steps require waiting for confirmation. They are good practice regardless of how this particular claim resolves.


