Morgan Services, Inc., a Chicago linen and uniform company, is sending letters warning that names and Social Security numbers may have been exposed. Five weeks earlier, a ransomware group claimed it had taken 477 GB of the company’s data.
What Morgan Services Has Reported
Morgan Services, Inc. is a family-owned linen and uniform rental and laundry company headquartered in Chicago. Founded in 1887, it serves hospitals, hotels and other businesses.
In a notice letter dated October 2, 2026, Morgan Services says it experienced “a cyber security incident” that may have involved the recipient’s information. The company filed the letter with Massachusetts regulators on October 6, 2026.
The letter does not say when the incident happened, when the company found it or how it happened. Massachusetts law bars a notice sent to its residents from describing the nature of a breach, so letters sent to people in other states may say more. The letter is signed by the company’s HR Manager.
A Ransomware Group Claimed 477 GB in August
On August 26, 2026, a ransomware group called AiLock listed Morgan Services on its leak website and claimed to hold about 477 GB of the company’s data, according to ransomware.live, a site that tracks these postings. Ransomware groups steal or lock a company’s files and threaten to publish them unless they are paid.
Morgan Services has not confirmed the claim, and its letter does not mention ransomware. It is not confirmed that the August claim and the October letter describe the same incident.
What Information Was Exposed?
According to the letter, the information at risk may include:
- First and last name
- Social Security number
The letter does not list any other types of information.
How Many People Were Affected?
Morgan Services has not disclosed a total. Massachusetts lists 213 of its residents as affected, according to the state’s data breach report. Because Morgan Services is based in Illinois, that count reflects only one state and is not a measure of the total.
What Is Morgan Services Offering?
Morgan Services is offering 24 months of single-bureau credit monitoring, a credit report and a credit score through Experian, at no cost. People must enroll within 90 days of the date on their letter. The letter says Morgan Services has seen no evidence of attempted or actual misuse of the information.
Your Information Is at Risk
A name and Social Security number together are enough for a criminal to apply for credit, file a false tax return or claim benefits in someone else’s name. A Social Security number usually cannot be changed, so the risk can last for years after a breach.
Do You Have Legal Options?
Companies that collect Social Security numbers, including employers that keep them in personnel and payroll records, have a duty to protect them and to notify people promptly when they are exposed. When that obligation is not met, affected individuals may have legal rights and remedies worth discussing with an attorney. Emery | Reddy is investigating this incident on behalf of people who received a notice letter.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review. No Fee Unless We Recover. Call 916.995.5968.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Frequently Asked Questions
Did Morgan Services have a data breach?
Morgan Services sent letters dated October 2, 2026 saying a cyber security incident may have involved people’s names and Social Security numbers. It filed the letter with Massachusetts regulators on October 6, 2026.
How many people were affected?
Morgan Services has not said. Massachusetts lists 213 of its residents. The national total has not been disclosed.
What information was exposed?
The letter lists:
- First and last name
- Social Security number
Is this connected to the ransomware attack claimed in August?
That has not been confirmed. A ransomware group called AiLock claimed on August 26, 2026 that it took about 477 GB of Morgan Services data. The company’s letter does not mention it.
Can criminals use a stolen Social Security number years later?
Yes. Unlike a credit card number, a Social Security number usually stays the same for life, so stolen numbers can be used or sold long after a breach. A credit freeze is the strongest free protection.
What should I do if I received a letter?
Take these steps:
- Enroll in the Experian monitoring within 90 days of the date on your letter
- Place a free credit freeze with Equifax, Experian and TransUnion
- Review your credit reports for accounts you do not recognize
- Be wary of calls, texts or emails that mention the breach or Morgan Services
- Keep your letter
Do I have a legal claim?
You may. Companies that collect Social Security numbers have a duty to protect them and to notify people promptly when they are exposed. If you received a Notice of Data Breach letter from Morgan Services, contact Emery | Reddy at 916.995.5968 or visit emeryreddy.com for a Free Case Review to see what you may qualify for. No Fee Unless We Recover.