Cyber Incident Victim: Morley
Date:
Aug 2021
Location:
United States of America
Summary
A ransomware attack targeted a business services provider serving major corporate clients, compromising personal data of over 521,000 individuals including employees, contractors, and client personnel. Threat actors exfiltrated sensitive information such as names, Social Security numbers, dates of birth, medical treatment details, health insurance records, and client identifiers prior to encrypting files. The company engaged cybersecurity specialists to conduct forensic analysis, confirming unauthorized data access but finding no evidence of subsequent misuse. Impacted parties received notifications with enrollment options for complimentary identity theft monitoring services covering two years. The incident prompted extensive review of affected systems and coordination with potentially exposed individuals affiliated with enterprise clients.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On August 1, 2021, Morley Companies Inc., a U.S.-based provider of business services to Fortune 500 and Global 100 clients, experienced a ransomware attack that compromised its digital environment. The incident rendered company data unavailable following file encryption by threat actors, who also exfiltrated sensitive personal information prior to deploying ransomware. Morley disclosed the breach in February 2022 after completing an investigation that determined unauthorized access to data belonging to 521,046 individuals, including employees, contractors, and client personnel. The compromised information encompassed full names, Social Security numbers, dates of birth, client ID numbers, medical diagnostic and treatment details, and health insurance information. The company acknowledged that attackers obtained this data from its systems but found no evidence of malicious use during their investigation.

Morley initiated response measures by engaging cybersecurity specialists to analyze the breach scope and employed unique data analysis methods to identify affected parties. Notification letters were prepared throughout late 2021, with contact information collection finalized by early 2022 to inform impacted individuals. The company offered all victims 24 months of complimentary identity theft protection services through IDX, including enrollment instructions distributed via mailed notifications. While the attack disrupted Morley’s operations through data unavailability, the primary impact centered on potential identity theft risks for those whose personal and medical information was stolen. The incident highlighted secondary exposure risks for employees of Morley’s corporate clients, though specific client names or contractual consequences remained undisclosed in public statements.
