• News/
  • https://www.theregister.com/2025/06/04/play_ransomware_infects_900_victims/

Play ransomware crims exploit SimpleHelp flaw in double-extortion schemes

The Register
·
Jessica Lyons
·
Published Jun 4, 2025
·
Updated

Groups linked with the Play ransomware have exploited more than 900 organizations, the FBI said Wednesday, and have developed a number of new techniques in their double-extortion campaigns - including exploiting a security flaw in remote-access tool SimpleHelp if orgs haven't patched it. This particular ransomware variant was among the top five targeting critical infrastructure last year. And according to a Wednesday cybersecurity advisory, the criminals don't seem to be slowing down in their double-extortion attacks, in which they first steal and encrypt sensitive data, then threaten to release it online unless the victims pay up. "Ransom notes do not include an initial ransom demand or payment instructions; rather, victims are instructed to contact the threat actors via email," the FBI, Cybersecurity and Infrastructure Security Agency, and Australian Signals Directorate's Cyber Security Centre said in a June 4 update to an earlier Play ransomware alert. The update includes new tactics, techniques, and procedures Play uses, along with current indicators of compromise to help network defenders protect their organizations from the ransomware crew. Among these: the ransomware notes contain a unique @gmx.de or @web[.]de email for communications. Plus, in a move that screams psychological manipulation, Play operators regularly call their victims and threaten to release their stolen data if they don't pay up. "These calls can be routed to a variety of phone numbers within the orga...

Read full article

Affected Software

3 affected components
SimpleHelp Remote-access tool
Fortinet FortiOS
Microsoft Exchange
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how Play ransomware has exploited a flaw in SimpleHelp and affected over 900 organizations through double-extortion schemes.

2

What security implications are discussed?

The article highlights the risks associated with double-extortion ransomware attacks and the exploitation of vulnerabilities in remote access software.

3

What products or software are affected?

The affected software includes SimpleHelp Remote-access tool, Fortinet FortiOS, and Microsoft Exchange.

4

How are the double-extortion schemes executed?

Attackers steal data and then demand a ransom for decryption while threatening to release the stolen information.

5

Which organization reported the increase in ransomware attacks?

The FBI reported the increase in ransomware attacks attributed to the Play ransomware group.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Play ransomware crims exploit SimpleHelp flaw in double-extortion schemes - SecAlerts