Ransomware Attack by Play Group Exposes Sensitive Data at GLIT
Ransomware Attack on Great Lakes International Trading by Play Group
Company Overview
Great Lakes International Trading, Inc. (GLIT) is a full-service import and export company specializing in processed foods, dried fruits, and grocery retail products. Founded in Traverse City, Michigan, GLIT has grown to become a significant player in the food and beverage industry. With an estimated revenue of $2 million, GLIT is considered a small to medium-sized enterprise.
Attack Overview
The ransomware group Play has claimed responsibility for a cyberattack on GLIT. The attack compromised private and personal confidential data, client documents, budget, payroll, accounting records, contracts, tax information, IDs, and financial information. The breach was announced on Play's dark web leak site, highlighting the severity of the data exposure.
Ransomware Group Profile
Play ransomware is a significant actor in the cybercrime landscape, known for targeting Linux systems. Associated with the Babuk code, Play ransomware has evolved to target ESXi lockers. The group, operated by Ransom House, initially focused on data theft but has since adopted cryptographic lockers. Play ransomware is characterized by its unique verbose ransom notes and the use of Sosemanuk for encryption.
Penetration and Vulnerabilities
Play ransomware actors have been observed using various hack tools and utilities after achieving initial access, such as AnyDesk, NetCat, and encoded PowerShell Empire scripts. The group's tactics include submitting binaries to VirusTotal containing these tools. GLIT's vulnerabilities likely stem from inadequate cybersecurity measures, making them a target for sophisticated ransomware groups like Play.
Impact on GLIT
The attack on GLIT has significant implications, given the sensitive nature of the compromised data. As a company specializing in the import and export of food products, the breach could affect their business operations and client trust. The exposure of financial and personal information also poses a risk to their stakeholders.
Sources:
- Great Lakes International Trading, Inc. Official Website
- LinkedIn Profile of Great Lakes International Trading, Inc.
- RocketReach Profile of Great Lakes International Trading, Inc.
- ZoomInfo Profile of Great Lakes International Trading, Inc.
- 6sense Profile of Great Lakes International Trading, Inc.
- Bloomberg Profile of Great Lakes International Trading, Inc.
- SentinelOne Report on Play Ransomware
- Sophos News on Ransomware Gangs
- TechTarget Definition of Ransomware
- UK Parliament Report on Ransomware
- Check Point Cyber Hub on Ransomware
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!