Morris Communications Company, parented by Questo, detected unusual activity on its network on October 9, 2025. An investigation confirmed that unauthorized access occurred between October 1 and October 9, 2025, resulting in files being accessed and exfiltrated by the Akira ransomware group. The breach exposed various types of personal data, including names, addresses, dates of birth, Social Security numbers, driver's license numbers, government ID numbers, passport numbers, tax information, financial account information, payment card information, and medical information. While the company began sending notification letters on July 17, 2026, the total number of affected individuals has not been publicly disclosed. Details surrounding the breach, such as the exact scope of affected customers and any further regulatory actions, may emerge as investigations continue and litigation progresses.