Groups linked with the Play ransomware have exploited more than 900 organizations, the FBI said Wednesday, and have developed a number of new techniques in their double-extortion campaigns - including exploiting a security flaw in remote-access tool SimpleHelp if orgs haven't patched it. This particular ransomware variant was among the top five targeting critical infrastructure last year. And according to a Wednesday cybersecurity advisory, the criminals don't seem to be slowing down in their double-extortion attacks, in which they first steal and encrypt sensitive data, then threaten to release it online unless the victims pay up. "Ransom notes do not include an initial ransom demand or payment instructions; rather, victims are instructed to contact the threat actors via email," the FBI, Cybersecurity and Infrastructure Security Agency, and Australian Signals Directorate's Cyber Security Centre said in a June 4 update to an earlier Play ransomware alert. The update includes new tactics, techniques, and procedures Play uses, along with current indicators of compromise to help network defenders protect their organizations from the ransomware crew. Among these: the ransomware notes contain a unique @gmx.de or @web[.]de email for communications. Plus, in a move that screams psychological manipulation, Play operators regularly call their victims and threaten to release their stolen data if they don't pay up. "These calls can be routed to a variety of phone numbers within the orga...
Play ransomware crims exploit SimpleHelp flaw in double-extortion schemes
The Register
·Jessica Lyons
·Published Jun 4, 2025
·Updated
Affected Software
3 affected components
SimpleHelp Remote-access tool
Fortinet FortiOS
Microsoft Exchange
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how Play ransomware has exploited a flaw in SimpleHelp and affected over 900 organizations through double-extortion schemes.
2
What security implications are discussed?
The article highlights the risks associated with double-extortion ransomware attacks and the exploitation of vulnerabilities in remote access software.
3
What products or software are affected?
The affected software includes SimpleHelp Remote-access tool, Fortinet FortiOS, and Microsoft Exchange.
4
How are the double-extortion schemes executed?
Attackers steal data and then demand a ransom for decryption while threatening to release the stolen information.
5
Which organization reported the increase in ransomware attacks?
The FBI reported the increase in ransomware attacks attributed to the Play ransomware group.