Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Samsung launches Galaxy Z Fold7, Z Flip7 and Z Flip7 FE

    Samsung launches Galaxy Watch8 series

    FTC’s ‘click to cancel’ subscription rules thrown out by judges

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Apple sued by shareholders for allegedly overstating AI progress

      June 22, 2025

      How far will AI go to defend its own survival?

      June 2, 2025

      The internet thinks this video from Gaza is AI. Here’s how we proved it isn’t.

      May 30, 2025

      Nvidia CEO hails Trump’s plan to rescind some export curbs on AI chips to China

      May 22, 2025

      AI poses a bigger threat to women’s work, than men’s, report says

      May 21, 2025
    • Business

      Cloudflare open-sources Orange Meets with End-to-End encryption

      June 29, 2025

      Google links massive cloud outage to API management issue

      June 13, 2025

      The EU challenges Google and Cloudflare with its very own DNS resolver that can filter dangerous traffic

      June 11, 2025

      These two Ivanti bugs are allowing hackers to target cloud instances

      May 21, 2025

      How cloud and AI transform and improve customer experiences

      May 10, 2025
    • Crypto

      Bitget Partners With UNTOLD Festival, Where Web3 Takes The Main Stage

      July 9, 2025

      Dogecoin (DOGE) Price Nears Key Resistance Again: Rally Or Another Rejection?

      July 9, 2025

      Fidelity Fuels Ethereum Buzz, But Bitcoin Sell Risk Stalls ETH Rally

      July 9, 2025

      BONK Jumps 60 % in a Week—Will Golden Cross Power a Breakout?

      July 9, 2025

      Crypto Firms in South Korea Could Soon Benefit from Government Subsidies and Tax Breaks

      July 9, 2025
    • Technology

      FTC’s ‘click to cancel’ subscription rules thrown out by judges

      July 9, 2025

      I put up these holiday lights last year—and they’re not coming down

      July 9, 2025

      Perplexity debuts Comet, a free AI browser (that currently costs $200)

      July 9, 2025

      I found the 10 best Prime Day PC tech deals under $50

      July 9, 2025

      Best Prime Day deals on Chromebooks (July 9)

      July 9, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Shop Now
    Tech AI Verse
    You are at:Home»Technology»FBI: Play ransomware breached 900 victims, including critical orgs
    Technology

    FBI: Play ransomware breached 900 victims, including critical orgs

    TechAiVerseBy TechAiVerseJune 5, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    FBI: Play ransomware breached 900 victims, including critical orgs
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    FBI: Play ransomware breached 900 victims, including critical orgs

    In an update to a joint advisory with CISA and the Australian Cyber Security Centre, the FBI said that the Play ransomware gang had breached roughly 900 organizations as of May 2025, three times the number of victims reported in October 2023.

    “Since June 2022, the Play (also known as Playcrypt) ransomware group has impacted a wide range of businesses and critical infrastructure in North America, South America, and Europe. Play ransomware was among the most active ransomware groups in 2024,” the FBI warned.

    “As of May 2025, FBI was aware of approximately 900 affected entities allegedly exploited by the ransomware actors.”

    Today’s update also notes that the gang uses recompiled malware in every attack, making it more difficult for security solutions to detect and block it. Additionally, some victims have been contacted via phone calls and threatened to pay the ransom to prevent their stolen data from being leaked online.

    Since the start of the year, initial access brokers with ties to Play ransomware operators have also exploited several vulnerabilities (CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728) in the remote monitoring and management tool in remote code execution attacks targeting U.S. organizations.

    In one such incident, unknown threat actors targeted vulnerable SimpleHelp RMM clients to create admin accounts, backdoored the compromised systems with Sliver beacons, potentially preparing them for future ransomware attacks.

    The Play ransomware-as-a-service (RaaS) operation

    The Play ransomware gang surfaced almost three years ago, with the first victims reaching out for help in BleepingComputer’s forums in June 2022. Before deploying ransomware on the victims’ networks, Play affiliates steal sensitive documents from compromised systems and use them to pressure victims into paying ransom demands under the threat of publishing the stolen data on the gang’s dark web leak site.

    However, unlike other ransomware operations, Play ransomware uses email as a negotiation channel and will not provide victims with a Tor negotiations page link.

    The ransomware gang also uses a custom VSS Copying Tool that helps steal files from shadow volume copies, even when used by other applications.

    Previous high-profile Play ransomware victims include cloud computing company Rackspace, the City of Oakland in California, Dallas County, car retailer giant Arnold Clark, the Belgian city of Antwerp, and, more recently, doughnut chain Krispy Kreme and American semiconductor supplier Microchip Technology.

    In guidance issued by the FBI, CISA, and the Australian Cyber Security Centre, security teams are urged to prioritize keeping their systems, software, and firmware up to date to reduce the likelihood that unpatched vulnerabilities are exploited in Play ransomware attacks.

    Defenders are also advised to implement multifactor authentication (MFA) across all services, focusing on VPN, webmail, and accounts with access to critical systems in their organizations’ networks.

    Additionally, they should maintain offline data backups and develop and test a recovery routine as part of their organization’s standard security practices.


    Why IT teams are ditching manual patch management

    Manual patching is outdated. It’s slow, error-prone, and tough to scale.

    Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleHacker arrested for breaching 5,000 hosting accounts to mine crypto
    Next Article Microsoft unveils free EU cybersecurity program for governments
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    FTC’s ‘click to cancel’ subscription rules thrown out by judges

    July 9, 2025

    I put up these holiday lights last year—and they’re not coming down

    July 9, 2025

    Perplexity debuts Comet, a free AI browser (that currently costs $200)

    July 9, 2025
    Leave A Reply Cancel Reply

    Top Posts

    New Akira ransomware decryptor cracks encryptions keys using GPUs

    March 16, 202527 Views

    OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits

    April 19, 202522 Views

    Rsync replaced with openrsync on macOS Sequoia

    April 7, 202519 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202517 Views
    Don't Miss
    Gadgets July 10, 2025

    Samsung launches Galaxy Z Fold7, Z Flip7 and Z Flip7 FE

    Samsung launches Galaxy Z Fold7, Z Flip7 and Z Flip7 FE Samsung has officially launched…

    Samsung launches Galaxy Watch8 series

    FTC’s ‘click to cancel’ subscription rules thrown out by judges

    I put up these holiday lights last year—and they’re not coming down

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Samsung launches Galaxy Z Fold7, Z Flip7 and Z Flip7 FE

    July 10, 20252 Views

    Samsung launches Galaxy Watch8 series

    July 10, 20252 Views

    FTC’s ‘click to cancel’ subscription rules thrown out by judges

    July 9, 20252 Views
    Most Popular

    Ethereum must hold $2,000 support or risk dropping to $1,850 – Here’s why

    March 12, 20250 Views

    Xiaomi 15 Ultra Officially Launched in China, Malaysia launch to follow after global event

    March 12, 20250 Views

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.