Ransomware dossier

Play

PlayCrypt. High-volume double extortion using intermittent encryption, heavy on unpatched edge devices and VPN/remote access. Rarely recruits publicly.

Claimed victims

958

Top region

US

Top sector

Professional Services

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2026-10-04Bold Spring NurseryAgriculture and Food ProductionUS
2026-10-04Silicon Valley GlassManufacturingUS
2026-09-30TitusTechnologyDE
2026-09-30Airtech Mechanical ServicesProfessional ServicesUS
2026-09-30Orth AutomobileManufacturingDE
2026-09-28Starr Whitehouse Landscape ArchitectsProfessional ServicesUS
2026-09-28Ever Ready First AidHealthcareUS
2026-09-21MetallcoManufacturingBR
2026-09-21HurleyOtherUS
2026-09-18Vista Plastic SolutionsManufacturingCA

Regions targeted

US 49CA 8DE 6GB 3NL 3BR 1IE 1RS 1

Sectors targeted

Professional Services 16Manufacturing 15Technology 13Retail & E-Commerce 9Agriculture and Food Production 6Financial Services 4

Suspected origin

Russia — Russian-speaking (OSINT, debated). Attribution reflects open-source consensus, not certainty.

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups