Play
PlayCrypt. High-volume double extortion using intermittent encryption, heavy on unpatched edge devices and VPN/remote access. Rarely recruits publicly.
Claimed victims
958
Top region
US
Top sector
Professional Services
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2026-10-04 | Bold Spring Nursery | Agriculture and Food Production | US |
| 2026-10-04 | Silicon Valley Glass | Manufacturing | US |
| 2026-09-30 | Titus | Technology | DE |
| 2026-09-30 | Airtech Mechanical Services | Professional Services | US |
| 2026-09-30 | Orth Automobile | Manufacturing | DE |
| 2026-09-28 | Starr Whitehouse Landscape Architects | Professional Services | US |
| 2026-09-28 | Ever Ready First Aid | Healthcare | US |
| 2026-09-21 | Metallco | Manufacturing | BR |
| 2026-09-21 | Hurley | Other | US |
| 2026-09-18 | Vista Plastic Solutions | Manufacturing | CA |
Regions targeted
Sectors targeted
Suspected origin
Russia — Russian-speaking (OSINT, debated). Attribution reflects open-source consensus, not certainty.
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.