Play Ransomware (Playcrypt): FBI/CISA/ASD Joint Advisory on Closed-Group Double Extortion Operation Impacting 900+ Entities Across North America, South America, Europe, and Australia

The FBI, CISA, and Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) published a joint advisory on CISA (originally December 18, 2023, updated June 4, 2025) covering Play ransomware (also known as Playcrypt), one of the most active ransomware groups of 2024. Active since June 2022, Play had impacted approximately 900 entities as of May 2025 across critical infrastructure, businesses, and public sector organizations in North America, South America, Europe, and Australia (first observed April 2023, most recently November 2023).

Closed-Group Model: Double Extortion, No Initial Ransom Demand, Unique GMX/Web.de Email per Victim

Play ransomware operates as a presumed closed group — not a Ransomware-as-a-Service (RaaS) open affiliate model — explicitly marketing itself as designed to "guarantee the secrecy of deals." The group employs double extortion: data is exfiltrated before encryption, and victims are threatened with public release if ransom is unpaid. Unusually, ransom notes contain no initial ransom demand or payment instructions; victims are directed to contact the group via email. Each victim is assigned a unique @gmx.de or @web[.]de email address for negotiations. A subset of victims are also contacted by telephone with direct threats of data release, adding social pressure to the extortion process.

TTPs and Recommended Mitigations

The advisory, updated to reflect TTPs observed through January 2025 FBI investigations, identifies Play ransomware actors as exploiting known vulnerabilities in internet-facing systems, targeting webmail and VPN access points where MFA is absent, and maintaining persistence for data exfiltration prior to encryption. The FBI/CISA/ASD joint guidance prioritizes: remediating known exploited vulnerabilities, enforcing MFA across all services (particularly webmail, VPN, and critical system access), maintaining offline data backups, implementing a tested recovery plan, and keeping all operating systems, software, and firmware current through regular patch cycles and vulnerability assessments.

Read the full analysis on IntelFusions