Ransomware Attack by Play Group Exposes Sensitive Data at GLIT

Incident Date:

June 12, 2024

World map

Overview

Title

Ransomware Attack by Play Group Exposes Sensitive Data at GLIT

Victim

Great Lakes International Trading

Attacker

Play

Location

Yorkville, USA

Wisconsin, USA

First Reported

June 12, 2024

Ransomware Attack on Great Lakes International Trading by Play Group

Company Overview

Great Lakes International Trading, Inc. (GLIT) is a full-service import and export company specializing in processed foods, dried fruits, and grocery retail products. Founded in Traverse City, Michigan, GLIT has grown to become a significant player in the food and beverage industry. With an estimated revenue of $2 million, GLIT is considered a small to medium-sized enterprise.

Attack Overview

The ransomware group Play has claimed responsibility for a cyberattack on GLIT. The attack compromised private and personal confidential data, client documents, budget, payroll, accounting records, contracts, tax information, IDs, and financial information. The breach was announced on Play's dark web leak site, highlighting the severity of the data exposure.

Ransomware Group Profile

Play ransomware is a significant actor in the cybercrime landscape, known for targeting Linux systems. Associated with the Babuk code, Play ransomware has evolved to target ESXi lockers. The group, operated by Ransom House, initially focused on data theft but has since adopted cryptographic lockers. Play ransomware is characterized by its unique verbose ransom notes and the use of Sosemanuk for encryption.

Penetration and Vulnerabilities

Play ransomware actors have been observed using various hack tools and utilities after achieving initial access, such as AnyDesk, NetCat, and encoded PowerShell Empire scripts. The group's tactics include submitting binaries to VirusTotal containing these tools. GLIT's vulnerabilities likely stem from inadequate cybersecurity measures, making them a target for sophisticated ransomware groups like Play.

Impact on GLIT

The attack on GLIT has significant implications, given the sensitive nature of the compromised data. As a company specializing in the import and export of food products, the breach could affect their business operations and client trust. The exposure of financial and personal information also poses a risk to their stakeholders.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.