Ransomware Attack Exposes Markdom Plastic Products' Data

Incident Date:

October 4, 2024

World map

Overview

Title

Ransomware Attack Exposes Markdom Plastic Products' Data

Victim

Markdom Plastic Products

Attacker

Play

Location

Scarborough, Canada

, Canada

First Reported

October 4, 2024

Ransomware Attack on Markdom Plastic Products by Play Group

Markdom Plastic Products, a prominent manufacturer in the injection-molded plastics sector, has recently been targeted by the Play ransomware group. This attack has exposed significant vulnerabilities within the company's cybersecurity infrastructure, leading to the unauthorized access of sensitive data.

Company Overview

Markdom Plastic Products, based in Toronto, Ontario, specializes in custom injection-molded plastic products, primarily serving the automotive and consumer goods industries. The company is recognized for its advanced two-shot injection molding technologies and its commitment to innovation, integrating Industry 4.0 technologies to enhance efficiency and product quality. With approximately 69 employees and an annual revenue of $16.7 million, Markdom stands out as a Tier 1 supplier known for high-quality standards and customer satisfaction.

Attack Overview

The Play ransomware group successfully infiltrated Markdom's network, compromising a wide array of sensitive data, including client documents, payroll records, and financial information. The breach highlights significant vulnerabilities in Markdom's cybersecurity defenses, which were exploited by the attackers to gain unauthorized access to critical data.

About the Play Ransomware Group

Active since June 2022, the Play ransomware group, also known as PlayCrypt, has been responsible for numerous high-profile attacks across various industries. Initially focusing on Latin America, the group has expanded its operations to North America, South America, and Europe. Play ransomware is known for its sophisticated attack methods, including exploiting vulnerabilities in RDP servers, FortiOS, and Microsoft Exchange, as well as using tools like Mimikatz for privilege escalation.

Penetration and Impact

The Play group distinguishes itself by employing custom tools and techniques to evade detection and maintain persistence within compromised networks. In the case of Markdom, the attackers likely exploited existing vulnerabilities in the company's network infrastructure, allowing them to access and exfiltrate sensitive data. The impact of this breach is significant, with the exposure of confidential information posing potential risks to Markdom's operations and reputation.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.