BreachCensus

morpheus

First seen January 7, 2025Active23 claimed victims

The claims below are reproduced as posted by morpheus on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group, targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments with ransom demands reaching up to 32 BTC (~$3M USD).

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Yue Ki IndustrialJuly 30, 2026ransomware_live
Kyowa Singapore Pte LtdJuly 21, 2026ransomware_live
Hansa Research Group Pvt. LtdJuly 6, 2026ransomware_live
Delegal Poindexter & Underkofler, P.A.June 25, 2026ransomware_live
HDFC FUNDJune 10, 2026ransomware_live
3I INFOTECHJune 8, 2026ransomware_live
BAYTECH A/SMay 14, 2026ransomware_live
GGIApril 21, 2026ransomware_live
SBCTANZANIAMarch 30, 2026ransomware_live
SURTECHINCFebruary 27, 2026ransomware_live
SUNSETWORLDRESORTSJanuary 29, 2026ransomware_live
VALLEREDONDODecember 27, 2025ransomware_live
SCIPIONIDecember 12, 2025ransomware_live
TeamglobalNovember 17, 2025ransomware_live
Landmark PropertiesMay 20, 2025ransomware_live
Metal Sales Manufacturing CorporationApril 4, 2025ransomware_live
Latronica Law Firm, P.CApril 3, 2025ransomware_live
Alora Pharmaceuticals, LLCApril 1, 2025ransomware_live
DZLFebruary 24, 2025ransomware_live
Dinizulu Law Group LTDFebruary 24, 2025ransomware_live
LYNXSPAJanuary 17, 2025ransomware_live
Pus GmbhJanuary 7, 2025ransomware_live
Arrotex PharmaceuticalsJanuary 7, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).