Miller and Smith Breached by Play Ransomware Group
Miller & Smith Targeted by Play Ransomware Group
Miller & Smith, a prominent real estate development firm based in Vienna, Virginia, has become the latest victim of a ransomware attack orchestrated by the notorious Play ransomware group. The attack, which occurred on November 20, 2024, has raised significant concerns about data security within the real estate sector.
Company Overview
Founded in 1964, Miller & Smith has established itself as a leading player in the Washington, D.C. metropolitan area's real estate market. The company is known for its innovative design and customer-centric approach, offering unique homes that cater to individual preferences. The firm employs approximately 68 people and reported revenues of $29.5 million as of 2024.
Attack Details
The Play ransomware group claims to have accessed a trove of sensitive data from Miller & Smith, including client documents, budget information, payroll records, accounting details, contracts, tax documents, IDs, and financial information. The exact size of the data leak remains undisclosed, but the breach underscores the vulnerabilities that real estate companies face in safeguarding confidential information.
About Play Ransomware Group
Emerging in June 2022, Play Ransomware, also known as PlayCrypt, is recognized for its sophisticated and targeted attacks. Unlike affiliate-based Ransomware-as-a-Service (RaaS) groups, Play operates with a closed structure, enhancing its secrecy and precision. The group is known for its intermittent encryption technique, which encrypts only portions of files, making detection by endpoint defenses more challenging. In 2024, Play collaborated with APT 45, a North Korean state-sponsored group, to incorporate advanced techniques in its operations.
Potential Vulnerabilities
Play's attack on Miller & Smith likely exploited vulnerabilities in the company's IT infrastructure. The group is known for leveraging remote code execution vulnerabilities and authentication bypass flaws to gain initial access. Given Miller & Smith's reliance on digital systems for managing real estate transactions and client data, the company may have been susceptible to such sophisticated cyber threats.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!