Dome Construction Hit by Play Ransomware Group in Cyber Attack

Incident Date: Nov 05, 2024

Attack Overview
VICTIM
Dome Construction
INDUSTRY
Construction
LOCATION
USA
ATTACKER
Play
FIRST REPORTED
November 5, 2024

Ransomware Attack on Dome Construction by Play Group

Dome Construction, a leading general contractor based in South San Francisco, has become the latest victim of a ransomware attack by the notorious Play ransomware group. The breach, discovered on November 6, 2024, has raised concerns about the cybersecurity vulnerabilities within the construction industry, which often deals with sensitive project and client data.

About Dome Construction

Founded in 1969, Dome Construction has grown from a small family-run business into a prominent player in the construction industry, particularly in the Bay Area. The company employs approximately 351 individuals and reported a revenue of around $287 million. Known for its innovative approaches, Dome specializes in sectors such as healthcare, life sciences, and tenant improvements. Their commitment to quality, transparency, and client satisfaction has set them apart in the industry. However, the reliance on digital infrastructure for project management and client communication makes them a potential target for cyber threats.

Details of the Attack

The Play ransomware group, active since June 2022, has claimed responsibility for the attack on Dome Construction. The group is known for targeting a wide range of industries, including construction, by exploiting vulnerabilities in RDP servers, FortiOS, and Microsoft Exchange. The attack on Dome Construction potentially compromised sensitive data, although the full extent of the data leak remains unclear. This incident underscores the persistent threat posed by ransomware groups to industries handling significant volumes of confidential information.

About the Play Ransomware Group

The Play ransomware group, also known as PlayCrypt, distinguishes itself by not including an initial ransom demand in its notes, directing victims to contact them via email instead. The group employs sophisticated methods to gain access to networks, such as exploiting known vulnerabilities and using tools like Mimikatz for privilege escalation. Their ability to disable antimalware solutions and maintain persistence on compromised systems makes them a formidable threat. The attack on Dome Construction highlights the need for effective cybersecurity measures to protect against such sophisticated cyber threats.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.