Diamond Brand Gear Faces Ransomware Threat from Play Group
Ransomware Attack on Diamond Brand Gear by Play Group
On November 20, Diamond Brand Gear, a renowned manufacturer of outdoor equipment based in Fletcher, North Carolina, became the latest victim of a ransomware attack orchestrated by the Play ransomware group.
About Diamond Brand Gear
Established in 1881, Diamond Brand Gear has built a reputation for producing high-quality outdoor gear, including wall tents, glamping tents, and hiking equipment. The company operates from an 85,000-square-foot facility and employs between 51 and 200 individuals. Known for its commitment to sustainability and community engagement, Diamond Brand emphasizes the use of upcycled materials and environmentally friendly practices in its manufacturing processes. This dedication to quality and innovation has made it a leader in the outdoor equipment sector.
Details of the Attack
The Play ransomware group claims to have accessed a variety of sensitive information from Diamond Brand Gear, including client documents, budget details, payroll records, accounting information, contracts, tax documents, IDs, and financial data. The exact size of the data leak remains undisclosed, but the breach underscores the significant impact such attacks can have on a company's operations and reputation.
About Play Ransomware Group
Emerging in June 2022, Play Ransomware, also known as PlayCrypt, is recognized for its technical sophistication and targeted campaigns. Unlike affiliate-based Ransomware-as-a-Service groups, Play maintains a closed operational structure, enhancing its secrecy and precision. The group is known for its intermittent encryption technique, which encrypts only portions of files, making detection by endpoint defenses more challenging. Play has targeted high-value sectors, including manufacturing, where operational disruption can have severe consequences.
Potential Vulnerabilities
Play's attack on Diamond Brand Gear likely exploited vulnerabilities in the company's IT infrastructure. The group is known for leveraging remote code execution vulnerabilities and authentication bypass flaws to gain initial access. Once inside, Play uses advanced tools for lateral movement and data exfiltration, maximizing its leverage over victims.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!