Play Ransomware Attack on Sea Force IX

Year

2023

Month

July

Reference number

20230702

Impact area

Shore

Incident location

USA

Incident country

USA

Victim country

USA

Victim identity

Sea Force IX

Victim Type

Company office

Method

Ransomware

Summary:

In July 2023, Sea Force IX, a company based in Florida, USA, known for its fine custom sport fishing yachts, fell victim to a Play ransomware attack. The attack was reported on July 19, 2023, and the information was scraped from the PLAY NEWS Onion Dark Web Tor Blog page. No files or stolen information were available for download at the time of the report. The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) issued a joint Cybersecurity Advisory (CSA) on Play ransomware. The advisory, titled #StopRansomware: Play Ransomware, details the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by the Play ransomware group, identified through FBI investigations as recently as October 2023. Play ransomware actors use a double-extortion model, encrypting systems after exfiltrating data, and have affected various businesses and critical infrastructure organizations across North America, South America, Europe, and Australia. The advisory encourages organizations to review and implement the provided recommendations to mitigate the risks and impacts of Play and other ransomware incidents.

Reference URL

https://www.cisa.gov/news-events/alerts/2023/12/18/fbi-cisa-and-asds-acsc-release-advisory-play-ransomware
https://www.redpacketsecurity.com/play-ransomware-victim-sea-force-ix/