Year2023 |
MonthJuly |
Reference number20230702 |
Impact areaShore |
Incident locationUSA |
Incident countryUSA |
Victim countryUSA |
Victim identitySea Force IX |
Victim TypeCompany office |
MethodRansomware |
In July 2023, Sea Force IX, a company based in Florida, USA, known for its fine custom sport fishing yachts, fell victim to a Play ransomware attack. The attack was reported on July 19, 2023, and the information was scraped from the PLAY NEWS Onion Dark Web Tor Blog page. No files or stolen information were available for download at the time of the report. The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) issued a joint Cybersecurity Advisory (CSA) on Play ransomware. The advisory, titled #StopRansomware: Play Ransomware, details the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by the Play ransomware group, identified through FBI investigations as recently as October 2023. Play ransomware actors use a double-extortion model, encrypting systems after exfiltrating data, and have affected various businesses and critical infrastructure organizations across North America, South America, Europe, and Australia. The advisory encourages organizations to review and implement the provided recommendations to mitigate the risks and impacts of Play and other ransomware incidents.