Ransomware Hits Dana Safety Supply by Play Group

Incident Date: Oct 29, 2024

Attack Overview
VICTIM
Dana Safety Supply
INDUSTRY
Business Services
LOCATION
USA
ATTACKER
Play
FIRST REPORTED
October 29, 2024

Ransomware Attack on Dana Safety Supply by Play Group

Dana Safety Supply, a leading distributor and service provider in the public safety equipment industry, has been targeted by the Play ransomware group. This attack, discovered on October 30, has compromised a significant amount of sensitive data, raising concerns about the impact on the company's operations and client security.

About Dana Safety Supply

Established over 30 years ago, Dana Safety Supply (DSS) is a prominent supplier of emergency vehicle equipment, tactical gear, and public safety solutions. The company is headquartered in Jacksonville, Florida, and operates 38 locations across the United States. With a workforce of 501 to 750 employees, DSS generates an estimated annual revenue of $12.5 million. The company is known for its extensive product offerings, including LED warning lighting, sirens, light bars, and tactical gear, as well as its commitment to quality service and customer satisfaction.

Attack Overview

The Play ransomware group has claimed responsibility for the attack on Dana Safety Supply. The breach has resulted in the exposure of private and personal confidential information, client documents, budget details, payroll records, and financial data. The full extent of the data leak is still unknown, but the compromised information could have severe implications for both the company and its clients, particularly law enforcement and public safety agencies.

About the Play Ransomware Group

Active since June 2022, the Play ransomware group, also known as PlayCrypt, has targeted various industries, including IT, transportation, and government entities. The group is known for exploiting vulnerabilities in RDP servers, FortiOS, and Microsoft Exchange to gain initial access. Play distinguishes itself by not including an initial ransom demand in its notes, instead directing victims to contact them via email. The group uses tools like Mimikatz for privilege escalation and employs defense evasion techniques to disable antimalware solutions.

Potential Vulnerabilities

Dana Safety Supply's extensive network and operational scale may have made it an attractive target for the Play ransomware group. The company's involvement in federal contracts and its handling of sensitive data related to public safety could have increased its vulnerability to such attacks. The breach highlights the importance of effective cybersecurity measures, especially for organizations dealing with critical infrastructure and sensitive information.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.