Morris Communications Suffers Major Data Breach in October 2025
Morris Communications Co., a privately held media company based in Augusta, Georgia, disclosed a significant data breach that occurred in October 2025. The company detected the incident on October 9, 2025, following unauthorized access between October 1 and October 9, 2025.
On November 3, 2025, the ransomware group Akira claimed responsibility, asserting it had exfiltrated 84 gigabytes of sensitive data. The stolen information reportedly included financial records (audit documents, payment details, invoices), employee and customer data (passports, driver’s licenses, Social Security numbers, medical records, birth/death certificates, email addresses, and phone numbers), as well as confidential business documents (non-disclosure agreements and other sensitive files).
Morris Communications confirmed in its disclosure that exposed consumer data included names, addresses, Social Security numbers, government IDs, financial account details, and medical information. The company plans to begin notifying affected individuals on or around July 17, 2026, and has published a notice regarding the incident on its website.
The full scope of the breach, including the number of impacted individuals, remains undisclosed.
Source: https://www.claimdepot.com/data-breach/morris-communications-2026
Morris Communications cybersecurity rating report: https://www.rankiteo.com/company/morris-communications
"id": "MOR1784220063",
"linkid": "morris-communications",
"type": "Ransomware",
"date": "10/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Media',
'location': 'Augusta, Georgia, USA',
'name': 'Morris Communications Co.',
'type': 'Media Company'}],
'customer_advisories': 'Planned notifications to affected individuals '
'starting July 17, 2026',
'data_breach': {'data_exfiltration': 'Yes',
'file_types_exposed': ['Audit documents',
'Payment details',
'Invoices',
'Passports',
'Driver’s licenses',
'Social Security numbers',
'Medical records',
'Birth/death certificates',
'Email addresses',
'Phone numbers',
'Non-disclosure agreements'],
'personally_identifiable_information': ['Names',
'Addresses',
'Social Security '
'numbers',
'Government IDs',
'Financial account '
'details',
'Medical information'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Financial records',
'Employee data',
'Customer data',
'Confidential business '
'documents']},
'date_detected': '2025-10-09',
'date_publicly_disclosed': '2025-11-03',
'description': 'Morris Communications Co., a privately held media company '
'based in Augusta, Georgia, disclosed a significant data '
'breach that occurred in October 2025. The company detected '
'unauthorized access between October 1 and October 9, 2025, '
'with the ransomware group Akira claiming responsibility and '
'exfiltrating 84 gigabytes of sensitive data, including '
'financial records, employee and customer data, and '
'confidential business documents.',
'impact': {'data_compromised': '84 gigabytes',
'identity_theft_risk': 'High',
'payment_information_risk': 'High'},
'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Akira'},
'references': [{'source': 'Company Disclosure'}],
'response': {'communication_strategy': 'Published a notice on the company '
'website; planned notifications to '
'affected individuals starting July '
'17, 2026'},
'threat_actor': 'Akira',
'title': 'Morris Communications Suffers Major Data Breach',
'type': 'Data Breach, Ransomware'}