On May 14, 2024, Morris Group International appeared on the LockBit 3.0 ransomware leak site, claiming that the company suffered a ransomware attack in which internal files were exfiltrated. The manufacturer of stainless steel toilets, engineered plumbing products, vacuum plumbing systems, drinking fountains, and electric water heaters operates 27 locations worldwide across 28 divisions. The leak-site listing does not specify the number of people affected or detail exactly which records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch morrisgroupint.com
Get alerted the next time morrisgroupint.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about morrisgroupint.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 panel states that Morris Group International’s data was obtained during a ransomware incident and is now published after the company did not meet the group’s demands. The disclosure indicates that internal files were exfiltrated, but provides no count of records, no list of specific data types such as customer names or employee Social Security numbers, and no exact date the intrusion occurred. Public mirrors of the leak site, including ransomware.live, preserve the original posting timestamp of May 14, 2024. The notification does not mention whether payment systems, customer databases, or employee records were specifically impacted.
Why This Matters for You and Your Family
When a company that supplies plumbing and sanitation products to commercial buildings, schools, hospitals, and homes is breached, the people whose information ends up in the stolen files are often customers, vendors, employees, and their dependents. Even without an exact victim count, the exposure of internal files frequently includes invoices, contracts, shipping addresses, contact details, and employee information. Any of those records can be used to launch targeted phishing, identity theft, or follow-on fraud against you or members of your household. The breach therefore carries direct consequences for ordinary families who interacted with any of the company’s 27 global locations.
Doxxing and Identity-Chain Risks
Stolen internal files rarely stay isolated. Attackers and subsequent buyers on underground forums routinely cross-reference exposed email addresses, phone numbers, and physical addresses with other breach data. This creates long identity chains that link your work email to personal accounts, children’s school records, or family gaming profiles. Once those connections surface, doxxing escalates quickly: harassers can locate your home, spoof your identity for loans, or hijack accounts that share the same password. Credential leaks like this one frequently cascade into gaming-account takeovers, especially for households where children use family email addresses for Roblox, Fortnite, or Steam.