Ransomware Attack on Levin Porter Associates

Incident Date:

May 22, 2024

World map

Overview

Title

Ransomware Attack on Levin Porter Associates

Victim

Levin Porter Associates

Attacker

Play

Location

Miamisburg, USA

Ohio, USA

First Reported

May 22, 2024

Ransomware Attack on Levin Porter Associates

Victim Overview

Levin Porter Associates, a renowned architecture, interior design, and planning firm based in Miamisburg, Ohio, was recently targeted by the cybercrime group Play in a ransomware attack. The company, founded in 1960 by Richard Levin, offers full design services and has a strong presence in the industry, known for its innovative use of technologies such as 3D laser scanning, drone services, and virtual reality.

Company Size and Standout Features

Levin Porter Associates is a substantial company with a significant presence in the architecture, interior design, and planning sectors. The firm's commitment to delivering high-quality services, extensive experience, and consistent award-winning track record set it apart from others in the industry. Their use of advanced technologies like 3D laser scanning, BIM, and thermal imaging further highlights their standout status.

Attack Details

The cybercriminals behind the Play ransomware attack on Levin Porter Associates exfiltrated sensitive data, including private and personal confidential information, client documents, budget details, payroll records, accounting data, contracts, tax information, IDs, and financial data. The ransom demand details have not been disclosed, underscoring the ongoing vulnerabilities faced by professional service firms.

Ransomware Group Profile

The Play ransomware group, operated by Ransom House, is known for targeting Linux systems and has evolved from data theft to deploying cryptographic lockers. The group shares similarities with Baseline Babuk in terms of encryption methods and operational tactics, posing a significant threat to organizations and individuals.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.