Ransomware Attack on RDI-USA: Play Ransomware Group

Incident Date:

May 22, 2024

World map

Overview

Title

Ransomware Attack on RDI-USA: Play Ransomware Group

Victim

RDI-USA

Attacker

Play

Location

Spartanburg, USA

South Carolina, USA

First Reported

May 22, 2024

Ransomware Attack on RDI-USA by Play Ransomware Group

Victim Profile: RDI-USA, Inc.

RDI-USA, Inc. is a leading provider of hospitality products and services, established in 2004. The company is headquartered in South Carolina and California, with a focus on delivering high-quality products at competitive prices to the hospitality industry. RDI-USA has over 2000 products in its portfolio, indicating a significant size and presence in the hospitality industry. The company stands out for its commitment to continuous improvement and innovation, offering custom programs to help customers stay ahead of the curve with cutting-edge products.

Attack Overview

The company was targeted by the cybercrime group Play in a ransomware attack. The attackers exfiltrated sensitive data, including private and personal confidential information, client documents, budget details, payroll records, accounting data, contracts, tax information, IDs, and financial data. Details about the ransom demand have not been disclosed.

Play Ransomware Group Profile

The Play ransomware group, operated by Ransom House, is known for targeting Linux systems and has evolved to deploy cryptographic lockers. The group shares similarities with Baseline Babuk in terms of file searching functionality and encryption methods, using Sosemanuk for encryption. Play ransomware actors have been observed submitting binaries containing various hack tools and utilities associated with ransomware group techniques after achieving initial access.

Company Vulnerabilities

RDI-USA's vulnerabilities in being targeted by threat actors include potential weaknesses in their cybersecurity defenses, such as outdated software, lack of employee training on cybersecurity best practices, and inadequate network security measures. The company's significant size and presence in the hospitality industry may have made it an attractive target for cybercriminals seeking to exploit valuable data for financial gain.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.