Ransomware Attack Hits Dirksen Screw Products by Play Group

Incident Date: Oct 29, 2024

Attack Overview
VICTIM
Dirksen Screw Products
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Play
FIRST REPORTED
October 29, 2024

Ransomware Attack on Dirksen Screw Products by Play Group

Dirksen Screw Products, a well-established manufacturer in the precision machining industry, has recently been targeted by the Play ransomware group. This attack has compromised sensitive data, posing significant risks to the company's operations and client privacy.

About Dirksen Screw Products

Founded in 1939, Dirksen Screw Products is a prominent player in the precision machining sector, located in Shelby Township, Michigan. The company specializes in manufacturing high-quality precision machined products and cold-formed components, serving industries such as aerospace, agriculture, construction, and mining machinery. With a facility spanning 87,000 square feet and employing approximately 50 individuals, Dirksen Screw Products emphasizes quality and specialized manufacturing processes. Their partnership with ATG Precision Products enhances their ability to provide tailored solutions, leveraging a broad spectrum of manufacturing techniques.

Attack Overview

The Play ransomware group has claimed responsibility for the attack on Dirksen Screw Products, compromising a range of sensitive data, including private and personal information, client documents, tax records, and identification details. This breach highlights the vulnerabilities in the company's cybersecurity measures, emphasizing the need for enhanced protection against such threats.

About the Play Ransomware Group

Active since June 2022, the Play ransomware group, also known as PlayCrypt, has been involved in numerous high-profile attacks across various industries. Initially focusing on Latin America, the group has expanded its operations to North America, South America, and Europe. Play ransomware distinguishes itself by using various methods to gain entry into networks, including exploiting RDP servers, FortiOS vulnerabilities, and Microsoft Exchange vulnerabilities. The group employs tools like Mimikatz for privilege escalation and uses custom tools to enumerate users and computers on compromised networks.

Potential Vulnerabilities

Dirksen Screw Products' reliance on advanced machinery and technology, while beneficial for production quality, may also present vulnerabilities that threat actors like the Play group can exploit. The company's focus on quality assurance and specialized manufacturing processes underscores the importance of effective cybersecurity measures to protect sensitive data and maintain operational integrity.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.