Ransomware Group intelligence
Play
ActiveTrack Play with 1349 published victims and 5 known leak locations in a single intelligence view.
Overview
Play is tracked by Breach House as a ransomware group with 1349 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 5 | Onion service | Up checked 1h ago | ipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onion |
| Leak location 4 | Onion service | Up checked 1h ago | j75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onion |
| Leak location 1 | Onion service | Down checked 1h ago | mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion |
| Leak location 3 | Onion service | Down checked 1h ago | mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion |
Top Activity Sectors (17)
- Public Sector 588
- Not identified 227
- Services 77
- Manufacturing / Engineering 72
- Communication / Marketing 66
- IT 63
- Finance / Legal / Insurance 54
- Construction / Real Estate 42
- Energy 21
- Agriculture / Food 19
- Transportation / Travel / Logistics 19
- Hospitality / Food & Beverage / Tourism 16
- Retail / E-commerce 15
- Telecommunications 11
- NGOs / Associations 6
- Healthcare / Pharma 4
- Education 2
Typical Attacks (28)
▼How Play typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Play, Playcrypt.
-
T1587.001 Malware Resource Development
What they do: Play developed and employ Playcrypt ransomware.
What that means: Adversaries may develop malware and malware components that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: Play has used multiple tools for discovery and defense evasion purposes on compromised hosts.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
What they do: Play has used valid VPN accounts to achieve initial access.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Play has used valid domain accounts for access.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Play has used valid local accounts to gain initial access.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.
What that means: Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Play has used a batch script to remove indicators of its presence on compromised hosts.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1027.010 Command Obfuscation Stealth
What they do: Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1070.004 File Deletion Stealth
What they do: Play has used tools including Wevtutil to remove malicious files from compromised hosts.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: Play has used tools to remove log files on targeted systems.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1003.001 LSASS Memory Credential Access
What they do: Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1016 System Network Configuration Discovery Discovery
What they do: Play has used the information-stealing tool Grixba to enumerate network information.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Play has used the information stealer Grixba to check for a list of security processes.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: Play has leveraged tools to enumerate system information.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Play has used the Grixba information stealer to list security files and processes.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1518.001 Security Software Discovery Discovery
What they do: Play has used the information-stealing tool Grixba to scan for anti-virus software.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Play has used Cobalt Strike to move laterally via SMB.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: Play has used WinRAR to compress files prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Play has used Cobalt Strike to download files to compromised machines.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1030 Data Transfer Size Limits Exfiltration
What they do: Play has split victims' files into chunks for exfiltration.
What that means: An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds.
-
T1048 Exfiltration Over Alternative Protocol Exfiltration
What they do: Play has used WinSCP to exfiltrate data to actor-controlled accounts.
What that means: Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Playcrypt can use AlphaVSS to delete shadow copies.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1657 Financial Theft Impact
What they do: Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (11)
▼Software Play has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
ReadMe2.txt
Your network has been encrypted. Your private, personal, corporate, confidential data has been stolen. If you do not resolve the issue, your data will be published on our leak portal. News portal, tor network links: ipi4tiumgzjsym6pyuzrfqrtwskokxokqannmd6sa24shvr7x5kxdvqd.onion j75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onion contact email: [email protected] PLAY Ransomware Team
ReadMe.txt
PLAY news portal, tor network links: mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion [email protected]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1349)
Search, filter and paginate the victim timeline for Play. Showing 1–100 of 1349.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | MEQ id32340 View details | Canada | Retail / E-commerce | ||
|
www.mobiliermeq.com operates within the Retail and E-commerce sector based in Canada, providing relevant commercial services aligned with its domain identity. As part of a threat-intelligence index, this entity is cataloged as a ransomware victim associated with the threat actor identified as 'play'. The listing reflects its inclusion in cyber threat reporting without disclosing specific incident details, data loss specifics, or confirmed breach evidence. This description maintains neutrality per strict analytical guidelines, focusing solely on the entity's classification within the ransomware victim context linked to the specified threat actor. The catalog entry serves informational purposes for threat-aware stakeholders monitoring retail and e-commerce sector vulnerabilities. |
|||||
| Ransomware | MEQ id32340 View details | Canada | Retail / E-commerce | ||
|
Canada |
|||||
| Ransomware | Figgins Family Wine Estates id32341 View details | United States | Other | ||
|
www.figginsfamily.com is an entity located in the United States operating within the Other sector. The domain represents a business entity cataloged within a threat-intelligence index under the designation of ransomware victim. The listing specifically associates this entity with the threat actor identified as 'play', indicating a cybersecurity incident classification relevant to ransomware activity. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are provided here to maintain factual neutrality. This description serves to document the entity's presence in the intelligence catalog based on verified threat-correlation data. |
|||||
| Ransomware | Figgins Family Wine Estates id32341 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | KRC Machine Tool Solutions id32342 View details | United States | Manufacturing / Engineering | ||
|
www.krcmachinetoolsolutions.com operates within the United States manufacturing and engineering sectors, providing machine tool solutions and industrial technology services. The entity is cataloged as a ransomware victim within the threat-intelligence index, with its association specifically tied to the threat actor 'play'. This listing type indicates documented exposure to ransomware activity relevant to industrial infrastructure. The description reflects the entity's sector context and verified association without disclosing unconfirmed incident details such as data stolen, ransom demands, or specific breach metrics. The inclusion underscores ongoing monitoring of ransomware impacts across manufacturing and engineering environments. |
|||||
| Ransomware | KRC Machine Tool Solutions id32342 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Meteor Group id32343 View details | Germany | Services | ||
|
www.meteor.de operates within the Services sector based in Germany (DE), providing professional services and digital solutions to clients. The entity is cataloged within this threat-intelligence index as a ransomware victim, with the associated threat actor identified as 'play'. This listing reflects documented cybersecurity intelligence regarding the organization's involvement in a ransomware incident, contributing to broader awareness of active threat patterns in the Services sector across European markets. The entry provides neutral context for security analysts tracking ransomware-related entities and their geographic and sectoral profiles. |
|||||
| Ransomware | Meteor Group id32343 View details | Germany | Services | ||
|
Germany |
|||||
| Ransomware | Be Media id31834 View details | — | |||
|
United States |
|||||
| Ransomware | Be Media id31834 View details | United States | — | ||
|
United States |
|||||
| Ransomware | Latoplast id31835 View details | Latvia | — | ||
|
Canada |
|||||
| Ransomware | Coltrane Systems id31831 View details | United States | — | ||
|
United States |
|||||
| Ransomware | Bridgeport Capital Services id31801 View details | United States | — | ||
|
United States |
|||||
| Ransomware | Sam Pack Auto Group id31802 View details | United States | — | ||
|
United States |
|||||
| Ransomware | Woodhaven Association id31803 View details | United States | — | ||
|
United States |
|||||
| Ransomware | MIE Solutions id31503 View details | United Kingdom | Manufacturing / Engineering | ||
|
Mie Solutions is a company based in the United Kingdom, operating in the manufacturing and engineering sector. The company provides various services and solutions to its clients. Mie Solutions was listed as a ransomware victim associated with play |
|||||
| Ransomware | MIE Solutions id31503 View details | United Kingdom | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Rilpa Enterprises id31504 View details | United States | IT | ||
|
Helis.com is a US-based company operating in the IT sector, providing various services and solutions. The company is located in the United States and caters to a range of clients. Helis.com was listed as a ransomware victim associated with play. |
|||||
| Ransomware | Rilpa Enterprises id31504 View details | United States | IT | ||
|
Canada |
|||||
| Ransomware | Marconi Industrial Services id31501 View details | Italy | Manufacturing / Engineering | ||
|
Marconi Spa is an Italian company operating in the manufacturing and engineering sector. The company is based in Italy and provides various services and products related to its sector. Marconi Spa is listed as a ransomware victim associated with play |
|||||
| Ransomware | Marconi Industrial Services id31501 View details | Italy | Manufacturing / Engineering | ||
|
Italy |
|||||
| Ransomware | Signature Services id31388 View details | United States | Finance / Legal / Insurance | ||
|
Signature Services is a company operating in the finance, legal, and insurance sector in the US. The company provides various services to its clients. Signature Services was listed as a ransomware victim associated with play |
|||||
| Ransomware | Signature Services id31388 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | GCATS Investments id31389 View details | United States | Services | ||
|
Gcatstx is a services company based in the US, providing various offerings to its clients. The company operates in the services sector, catering to a range of customers. Gcatstx was listed as a ransomware victim associated with play |
|||||
| Ransomware | GCATS Investments id31389 View details | United States | Services | ||
|
United States |
|||||
| Ransomware | Platinum Group id31390 View details | Singapore | Finance / Legal / Insurance | ||
|
Platinum-grp.com is a company based in Singapore, operating in the finance, legal, and insurance sector, offering various services to its clients. The company's specific offerings and services are not well-documented, but it is known to be part of the financial and legal services industry in Singapore. Platinum-grp.com was listed as a ransomware victim associated with play. |
|||||
| Ransomware | Platinum Group id31390 View details | Singapore | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Platinum Group id31390 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | First Tek id31234 View details | Taiwan, Province of China | IT | ||
|
First-tek.com is an IT company based in Taiwan, providing various IT services. The company operates in the IT sector, offering a range of solutions. First-tek.com was listed as a ransomware victim associated with play |
|||||
| Ransomware | First Tek id31234 View details | Taiwan, Province of China | IT | ||
|
United States |
|||||
| Ransomware | First Tek id31234 View details | United States | IT | ||
|
United States |
|||||
| Ransomware | Preferred Financial Group id31235 View details | United States | Finance / Legal / Insurance | ||
|
Preferredfinancial.com is a financial services company based in the United States, operating in the finance, legal, and insurance sector. The company provides financial solutions to its clients. Preferredfinancial.com was listed as a ransomware victim associated with play |
|||||
| Ransomware | Preferred Financial Group id31235 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | The Butcher Brothers id31148 View details | United States | Agriculture / Food | ||
|
The Butcher Brothers Corp is a US-based company operating in the agriculture and food sector, likely involved in meat production and distribution. As a player in this sector, the company would handle various aspects of the food supply chain. The Butcher Brothers Corp was listed as a ransomware victim associated with play |
|||||
| Ransomware | The Butcher Brothers id31148 View details | United States | Agriculture / Food | ||
|
United States |
|||||
| Ransomware | Sigma Plastics Group id31149 View details | United States | Manufacturing / Engineering | ||
|
Sigma Plastics Group is a US-based company operating in the manufacturing and engineering sector, offering various products and services. The company is involved in the production of plastic materials and related products. Sigma Plastics Group was listed as a ransomware victim associated with play |
|||||
| Ransomware | Sigma Plastics Group id31149 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Cambridge Management id31150 View details | United States | Finance / Legal / Insurance | ||
|
Cambridgemgmt.net operates in the finance, legal, and insurance sector in the US, providing various services to its clients. The company's specific offerings are not publicly disclosed, but it is generally involved in management services. Cambridgemgmt.net was listed as a ransomware victim associated with play |
|||||
| Ransomware | Cambridge Management id31150 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Record Go Alquiler id30813 View details | Argentina | Transportation / Travel / Logistics | ||
|
Record Rent a Car is a transportation company based in Argentina, operating in the travel and logistics sector, offering car rental services to its customers. The company provides a range of vehicles for rent, catering to the needs of travelers and businesses. Record Rent a Car was listed as a ransomware victim associated with play. |
|||||
| Ransomware | Record Go Alquiler id30813 View details | Argentina | Transportation / Travel / Logistics | ||
|
Spain |
|||||
| Ransomware | Record Go Alquiler id30813 View details | Spain | Transportation / Travel / Logistics | ||
|
Spain |
|||||
| Ransomware | Restaurant Depot id30814 View details | United States | Retail / E-commerce | ||
|
Restaurant Depot is a US-based e-commerce company operating in the retail sector, specifically catering to the food service industry. The company offers a wide range of products and services to its customers. Restaurant Depot was listed as a ransomware victim associated with play. |
|||||
| Ransomware | Restaurant Depot id30814 View details | United States | Retail / E-commerce | ||
|
United States |
|||||
| Ransomware | The DeBruler id30815 View details | Malta | Finance / Legal / Insurance | ||
|
Tax-mt.com is a financial services entity based in Malta, operating in the finance, legal, and insurance sector. The company likely provides tax-related services to individuals and businesses. Tax-mt.com was listed as a ransomware victim associated with play |
|||||
| Ransomware | The DeBruler id30815 View details | Malta | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | The DeBruler id30815 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Tax MT id30739 View details | Malta | Finance / Legal / Insurance | ||
|
Tax-mt.com operates in the finance, legal, and insurance sector in Malta, providing tax-related services. The company likely offers various financial and tax consulting services to individuals and businesses. Tax-mt.com was listed as a ransomware victim associated with play |
|||||
| Ransomware | Tax MT id30739 View details | Malta | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Kreysler & Associates id30736 View details | United States | Manufacturing / Engineering | ||
|
Kreysler is a US-based company operating in the manufacturing and engineering sector, providing various services and products. The company is involved in the design, development, and production of complex systems and components. Kreysler was listed as a ransomware victim associated with play |
|||||
| Ransomware | Kreysler & Associates id30736 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Boston Electric and Telephone id30626 View details | United States | Finance / Legal / Insurance | ||
|
Betcorp is a US-based company operating in the finance, legal, and insurance sector, providing various financial services. The company is located in the United States and offers a range of financial products. Betcorp was listed as a ransomware victim associated with play |
|||||
| Ransomware | Boston Electric and Telephone id30626 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Wring Group id30627 View details | United Kingdom | Construction / Real Estate | ||
|
Wring Group is a UK-based company operating in the construction and real estate sector, providing various services to clients in Great Britain. The company's offerings cater to the needs of the construction and real estate industries. Wring Group was listed as a ransomware victim associated with play |
|||||
| Ransomware | Wring Group id30627 View details | United Kingdom | Construction / Real Estate | ||
|
United Kingdom |
|||||
| Ransomware | AG Scholtes id30621 View details | Netherlands | Manufacturing / Engineering | ||
|
Agscholtes NL is a company based in the Netherlands, operating in the manufacturing and engineering sector. The company likely provides various services and products related to its sector, although specific details are not readily available. Agscholtes NL was listed as a ransomware victim associated with play |
|||||
| Ransomware | AG Scholtes id30621 View details | Netherlands | Manufacturing / Engineering | ||
|
Netherlands |
|||||
| Ransomware | Andorra Life id30622 View details | Andorra | Retail / E-commerce | ||
|
Andorralife is an e-commerce company based in Andorra, operating in the retail sector. The company likely offers various products and services to customers in Andorra and possibly beyond. Andorralife is listed as a ransomware victim associated with play |
|||||
| Ransomware | Andorra Life id30622 View details | Andorra | Retail / E-commerce | ||
|
United States |
|||||
| Ransomware | Svensk Direktreklam id30623 View details | Sweden | NGOs / Associations | ||
|
Sveriges Dövas Riksförbund, or www.sdr.se, is a Swedish organization that advocates for the rights and interests of deaf and hard of hearing individuals in Sweden. The organization operates in the NGOs and associations sector, providing various services and support to its members. Sveriges Dövas Riksförbund is headquartered in Sweden and focuses on promoting equality and accessibility for deaf and hard of hearing people. It was listed as a ransomware victim associated with play |
|||||
| Ransomware | Svensk Direktreklam id30623 View details | Sweden | NGOs / Associations | ||
|
Sweden |
|||||
| Ransomware | Preneed Funeral Programs id30323 View details | United States | Finance / Legal / Insurance | ||
|
Preneed.net operates in the finance and insurance sector in the United States, providing services related to pre-need insurance and financial planning. The company's services cater to individuals and families seeking to plan for future financial needs. Preneed.net was listed as a ransomware victim associated with play |
|||||
| Ransomware | Preneed Funeral Programs id30323 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Kevin Bao Lenguyen id30325 View details | Other | |||
|
Kblaa.com is an entity operating in the other sector. The specifics of its offerings and location are not well-documented. Kblaa.com was listed as a ransomware victim associated with play. |
|||||
| Ransomware | Kevin Bao Lenguyen id30325 View details | Other | |||
|
United States |
|||||
| Ransomware | United Infrastructure id30326 View details | United States | Construction / Real Estate | ||
|
United Infrastructure is a company operating in the construction and real estate sector in the US. The company is involved in various infrastructure projects. United Infrastructure was listed as a ransomware victim associated with play |
|||||
| Ransomware | United Infrastructure id30326 View details | United States | Construction / Real Estate | ||
|
United Kingdom |
|||||
| Ransomware | Locati Architects id30250 View details | Australia | Construction / Real Estate | ||
|
Locati Architects is a company based in Australia, operating in the construction and real estate sector, providing architectural services. The company is involved in various projects, contributing to the development of the Australian construction industry. Locati Architects was listed as a ransomware victim associated with play |
|||||
| Ransomware | Locati Architects id30250 View details | Australia | Construction / Real Estate | ||
|
United States |
|||||
| Ransomware | Silvestri & Associates Insurance id30251 View details | United States | Finance / Legal / Insurance | ||
|
Silvestri and Associates is a US-based company operating in the finance, legal, and insurance sector, providing various services to its clients. The company is located in the United States and offers a range of services tailored to the financial, legal, and insurance industries. Silvestri and Associates was listed as a ransomware victim associated with play |
|||||
| Ransomware | Silvestri & Associates Insurance id30251 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Western Construction id30137 View details | United States | Construction / Real Estate | ||
|
Wciboise is a company based in the US, operating in the construction and real estate sector. The company likely provides various services related to construction and real estate in its local area. Wciboise was listed as a ransomware victim associated with play |
|||||
| Ransomware | Western Construction id30137 View details | United States | Construction / Real Estate | ||
|
United States |
|||||
| Ransomware | J&J Gaming id30049 View details | United States | IT | ||
|
JJGaming is an IT company based in the US, providing gaming-related services. The company operates in the IT sector, offering various gaming solutions. JJGaming was listed as a ransomware victim associated with play |
|||||
| Ransomware | J&J Gaming id30049 View details | United States | IT | ||
|
United States |
|||||
| Ransomware | Kuhnline id30050 View details | Germany | Manufacturing / Engineering | ||
|
Kuhnline is a company based in Germany that operates in the manufacturing and engineering sector. The company likely provides various products and services related to these fields. Kuhnline was listed as a ransomware victim associated with play |
|||||
| Ransomware | Kuhnline id30050 View details | Germany | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Benchmark Industrial Supply id30043 View details | United States | Manufacturing / Engineering | ||
|
Benchmark Inc is a US-based company operating in the manufacturing and engineering sector. The company provides various services and products to its clients. Benchmark Inc was listed as a ransomware victim associated with play |
|||||
| Ransomware | Benchmark Industrial Supply id30043 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Greg Crosslin id29956 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Integrated Technologies id29958 View details | IT | |||
|
United States |
|||||
| Ransomware | eurOptimum id29959 View details | Germany | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | Mundt and Associates id29734 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | Rainbow Distributors USA id29735 View details | United States | Retail / E-commerce | ||
|
United States |
|||||
| Ransomware | Pearson Ford id29661 View details | United Kingdom | Retail / E-commerce | ||
|
United States |
|||||
| Ransomware | Urschel Laboratories id29627 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Dallis Law Firm id29628 View details | United States | Finance / Legal / Insurance | ||
|
United States |
|||||
| Ransomware | The Chapel id29629 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
United States |
|||||
| Ransomware | Corley MFG id29630 View details | United States | Manufacturing / Engineering | ||
|
United States |
|||||
| Ransomware | Digitall Graphics id29538 View details | Canada | IT | ||
|
Canada |
|||||
| Ransomware | Hightower Communications id29539 View details | United States | Construction / Real Estate | ||
|
United States |
|||||
| Ransomware | GW Mechanical id29507 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | NL Fisher id29508 View details | Netherlands | Other | ||
|
Canada |
|||||
| Ransomware | Round Hill Country Club id29509 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | Legend Networking & Telecom id29510 View details | United States | Telecommunications | ||
|
United States |
|||||
| Ransomware | MyPillow id29511 View details | United States | Other | ||
|
United States |
|||||
| Ransomware | De Waard Transport id29513 View details | Netherlands | Other | ||
|
Netherlands |
|||||
| Ransomware | Zuther Hautmann id29270 View details | Germany | Other | ||
|
United States |
|||||
| Ransomware | Infoworld Membership Systems id29097 View details | Other | |||
|
United States |
|||||
| Ransomware | Town Car International id29098 View details | United States | Other | ||
|
United States |
|||||