Ransomware Attack by Play Group Exposes Sensitive Data at GLIT
Incident Date:
June 12, 2024
Overview
Title
Ransomware Attack by Play Group Exposes Sensitive Data at GLIT
Victim
Great Lakes International Trading
Attacker
Play
Location
First Reported
June 12, 2024
Ransomware Attack on Great Lakes International Trading by Play Group
Company Overview
Great Lakes International Trading, Inc. (GLIT) is a full-service import and export company specializing in processed foods, dried fruits, and grocery retail products. Founded in Traverse City, Michigan, GLIT has grown to become a significant player in the food and beverage industry. With an estimated revenue of $2 million, GLIT is considered a small to medium-sized enterprise.
Attack Overview
The ransomware group Play has claimed responsibility for a cyberattack on GLIT. The attack compromised private and personal confidential data, client documents, budget, payroll, accounting records, contracts, tax information, IDs, and financial information. The breach was announced on Play's dark web leak site, highlighting the severity of the data exposure.
Ransomware Group Profile
Play ransomware is a significant actor in the cybercrime landscape, known for targeting Linux systems. Associated with the Babuk code, Play ransomware has evolved to target ESXi lockers. The group, operated by Ransom House, initially focused on data theft but has since adopted cryptographic lockers. Play ransomware is characterized by its unique verbose ransom notes and the use of Sosemanuk for encryption.
Penetration and Vulnerabilities
Play ransomware actors have been observed using various hack tools and utilities after achieving initial access, such as AnyDesk, NetCat, and encoded PowerShell Empire scripts. The group's tactics include submitting binaries to VirusTotal containing these tools. GLIT's vulnerabilities likely stem from inadequate cybersecurity measures, making them a target for sophisticated ransomware groups like Play.
Impact on GLIT
The attack on GLIT has significant implications, given the sensitive nature of the compromised data. As a company specializing in the import and export of food products, the breach could affect their business operations and client trust. The exposure of financial and personal information also poses a risk to their stakeholders.
Sources:
- Great Lakes International Trading, Inc. Official Website
- LinkedIn Profile of Great Lakes International Trading, Inc.
- RocketReach Profile of Great Lakes International Trading, Inc.
- ZoomInfo Profile of Great Lakes International Trading, Inc.
- 6sense Profile of Great Lakes International Trading, Inc.
- Bloomberg Profile of Great Lakes International Trading, Inc.
- SentinelOne Report on Play Ransomware
- Sophos News on Ransomware Gangs
- TechTarget Definition of Ransomware
- UK Parliament Report on Ransomware
- Check Point Cyber Hub on Ransomware
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.