Universal Companies Hit by Play Ransomware Exposing Data

Incident Date:

October 10, 2024

World map

Overview

Title

Universal Companies Hit by Play Ransomware Exposing Data

Victim

Universal Companies, Inc.

Attacker

Play

Location

Abingdon, USA

Virginia, USA

First Reported

October 10, 2024

Ransomware Attack on Universal Companies by Play Group

Universal Companies, Inc., a leading supplier in the spa and wellness industry, has fallen victim to a ransomware attack orchestrated by the notorious Play ransomware group. This attack has exposed a significant amount of sensitive data, posing a substantial threat to the company's operations and its clients' privacy.

About Universal Companies

Universal Companies, headquartered in Abingdon, Virginia, is a prominent distributor of spa and wellness products, serving over 84,000 customers across 47 countries. Founded in 1982, the company offers an extensive catalog of over 27,000 products, including spa equipment, skincare items, and wellness solutions. Their commitment to quality has earned them accolades such as the American Spa Professional’s Choice Award. Despite their success, the company has faced challenges with customer service, as indicated by low ratings on platforms like the Better Business Bureau.

Details of the Attack

The Play ransomware group has claimed responsibility for the attack on Universal Companies, gaining access to a wide array of sensitive data, including client documents, payroll records, and financial data. The group has announced plans to release a full data dump, scheduled for October 11, posing a significant threat to the privacy and security of affected individuals and the organization.

About the Play Ransomware Group

Active since June 2022, the Play ransomware group, also known as PlayCrypt, has targeted various industries, including IT, transportation, and government entities. The group is known for its sophisticated attack methods, exploiting vulnerabilities in RDP servers, FortiOS, and Microsoft Exchange. Unlike typical ransomware groups, Play does not include an initial ransom demand in its notes, directing victims to contact them via email instead.

Potential Vulnerabilities

Universal Companies' extensive digital infrastructure and global reach may have made it an attractive target for the Play group. The company's reliance on digital systems for managing client data and operations could have provided multiple entry points for the attackers. The Play group likely exploited vulnerabilities in the company's network, potentially through compromised VPN accounts or unpatched software vulnerabilities.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.