Ransomware Attack Exposes Corbin Turf & Ornamental Supply's Data Vulnerabilities

Incident Date:

June 12, 2024

World map

Overview

Title

Ransomware Attack Exposes Corbin Turf & Ornamental Supply's Data Vulnerabilities

Victim

Corbin Turf & Ornamental Supply

Attacker

Play

Location

Greenville, USA

South Carolina, USA

First Reported

June 12, 2024

Ransomware Attack on Corbin Turf & Ornamental Supply by Play Group

Company Overview

Corbin Turf & Ornamental Supply, Inc., headquartered in Greenville, South Carolina, is a leading distributor in the turf and ornamental industry. Founded in 1983 by Don Corbin, the company has grown to serve golf course superintendents, athletic field managers, and other turf professionals. With an estimated revenue of $5.5 million and fewer than 25 employees, Corbin Turf is known for its high-quality products and expert advice in lawn care, landscaping, and plant maintenance.

Attack Overview

The ransomware group Play has claimed responsibility for a cyberattack on Corbin Turf & Ornamental Supply. The attack, disclosed via the group's dark web leak site, compromised private and personal confidential data, including client documents, budget, payroll, accounting, contracts, taxes, IDs, and financial information. This breach highlights the vulnerabilities of small to medium-sized enterprises in the agriculture sector, which often lack robust cybersecurity measures.

About the Play Ransomware Group

Play ransomware, operated by Ransom House, is a significant actor in the cybercrime landscape, known for targeting Linux systems. Initially linked to the Babuk code, Play ransomware has evolved to target ESXi lockers. The group is notorious for its sophisticated tactics, including the use of Sosemanuk for encryption and a unique verbose ransom note that provides explicit instructions to victims.

Penetration Tactics

Play ransomware actors typically gain initial access through vulnerabilities in network security, often using tools like AnyDesk, NetCat, and encoded PowerShell Empire scripts. The group's ability to submit binaries to VirusTotal containing various hack tools and utilities demonstrates their advanced capabilities in breaching systems. Corbin Turf's relatively small size and limited cybersecurity infrastructure may have made it an attractive target for such a sophisticated ransomware group.

Impact on Corbin Turf & Ornamental Supply

The attack on Corbin Turf & Ornamental Supply underscores the critical need for enhanced cybersecurity measures in the agriculture sector. The breach not only jeopardizes the company's financial stability but also risks the trust and confidence of its clients. As a family-owned business with a reputation for integrity and excellence, the impact of this ransomware attack could have long-lasting repercussions on its operations and customer relationships.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.