Diamond Brand Gear Faces Ransomware Threat from Play Group

Incident Date: Nov 19, 2024

Attack Overview
VICTIM
Diamond Brand Gear
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Play
FIRST REPORTED
November 19, 2024

Ransomware Attack on Diamond Brand Gear by Play Group

On November 20, Diamond Brand Gear, a renowned manufacturer of outdoor equipment based in Fletcher, North Carolina, became the latest victim of a ransomware attack orchestrated by the Play ransomware group.

About Diamond Brand Gear

Established in 1881, Diamond Brand Gear has built a reputation for producing high-quality outdoor gear, including wall tents, glamping tents, and hiking equipment. The company operates from an 85,000-square-foot facility and employs between 51 and 200 individuals. Known for its commitment to sustainability and community engagement, Diamond Brand emphasizes the use of upcycled materials and environmentally friendly practices in its manufacturing processes. This dedication to quality and innovation has made it a leader in the outdoor equipment sector.

Details of the Attack

The Play ransomware group claims to have accessed a variety of sensitive information from Diamond Brand Gear, including client documents, budget details, payroll records, accounting information, contracts, tax documents, IDs, and financial data. The exact size of the data leak remains undisclosed, but the breach underscores the significant impact such attacks can have on a company's operations and reputation.

About Play Ransomware Group

Emerging in June 2022, Play Ransomware, also known as PlayCrypt, is recognized for its technical sophistication and targeted campaigns. Unlike affiliate-based Ransomware-as-a-Service groups, Play maintains a closed operational structure, enhancing its secrecy and precision. The group is known for its intermittent encryption technique, which encrypts only portions of files, making detection by endpoint defenses more challenging. Play has targeted high-value sectors, including manufacturing, where operational disruption can have severe consequences.

Potential Vulnerabilities

Play's attack on Diamond Brand Gear likely exploited vulnerabilities in the company's IT infrastructure. The group is known for leveraging remote code execution vulnerabilities and authentication bypass flaws to gain initial access. Once inside, Play uses advanced tools for lateral movement and data exfiltration, maximizing its leverage over victims.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.