Ransomware Attack by Play Group Exposes Sensitive Data at GLIT

Incident Date: Jun 12, 2024

Attack Overview
VICTIM
Great Lakes International Trading
INDUSTRY
Software
LOCATION
USA
ATTACKER
Play
FIRST REPORTED
June 12, 2024

Ransomware Attack on Great Lakes International Trading by Play Group

Company Overview

Great Lakes International Trading, Inc. (GLIT) is a full-service import and export company specializing in processed foods, dried fruits, and grocery retail products. Founded in Traverse City, Michigan, GLIT has grown to become a significant player in the food and beverage industry. With an estimated revenue of $2 million, GLIT is considered a small to medium-sized enterprise.

Attack Overview

The ransomware group Play has claimed responsibility for a cyberattack on GLIT. The attack compromised private and personal confidential data, client documents, budget, payroll, accounting records, contracts, tax information, IDs, and financial information. The breach was announced on Play's dark web leak site, highlighting the severity of the data exposure.

Ransomware Group Profile

Play ransomware is a significant actor in the cybercrime landscape, known for targeting Linux systems. Associated with the Babuk code, Play ransomware has evolved to target ESXi lockers. The group, operated by Ransom House, initially focused on data theft but has since adopted cryptographic lockers. Play ransomware is characterized by its unique verbose ransom notes and the use of Sosemanuk for encryption.

Penetration and Vulnerabilities

Play ransomware actors have been observed using various hack tools and utilities after achieving initial access, such as AnyDesk, NetCat, and encoded PowerShell Empire scripts. The group's tactics include submitting binaries to VirusTotal containing these tools. GLIT's vulnerabilities likely stem from inadequate cybersecurity measures, making them a target for sophisticated ransomware groups like Play.

Impact on GLIT

The attack on GLIT has significant implications, given the sensitive nature of the compromised data. As a company specializing in the import and export of food products, the breach could affect their business operations and client trust. The exposure of financial and personal information also poses a risk to their stakeholders.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.