Ransomware victim disclosure
← All victimsKaiserAir
Claimed by Play · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Play
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation/Logistics
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileKaiserAir is a full-service aviation company based in the San Francisco Bay Area, California, with over 75 years of operation. The company provides private jet charter (FAA Part 135), airliner charter (737, Part 121), aircraft management (Part 91), and MRO/maintenance (Part 145) services. It operates two Fixed Base Operations (FBOs) at Oakland International Airport (KOAK) and Santa Rosa Airport (KSTS).
- Industry
- Private Jet Charter & Aviation Services
- Address
- Oakland (KOAK) and Santa Rosa (KSTS), San Francisco Bay Area, California, United States
Attack summary
Severity: high — Data has been published (not merely listed), confirming exfiltration. KaiserAir handles PII for high-net-worth private jet clients and operates regulated aviation services (FAA Parts 91/121/135/145), meaning exfiltrated data likely includes sensitive passenger PII, financial records, and aviation operational data. Publication without ransom payment escalates the risk.The Play ransomware group claims an attack on KaiserAir and has published data (disclosed_status: data_published), indicating exfiltration of company data. No specific ransom amount or data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Client/passenger personal information
- Flight operations records
- Aircraft management documents
- Employee/HR records
- Financial records
- Maintenance and regulatory compliance documents
What the group claims
United States
The leak post
captured from the group's site| Play ransomware HAS NEVER PROVIDED AND DOES NOT PROVIDE THE RaaS, read the FAQ page.WE NEVER WRITES FIRST, IF SOMEONE WRITES TO YOU, THEY ARE SCAMMERS.we'll buy your access: 75tkvxemb6zpyk3fbl3mwm32jklc2sdjacb3kazrioamopbfn2w2z5qd.onionIf we have not responded to you by email within 12 hours, please leave your contact information on the website in the contact tab. | | --- | | EMA Engineering & Consulting👁️ views: 321added: 2026-05-07publication date: 2026-05-11 | Accessoires Outillage Ltee👁️ views: 280added: 2026-05-07publication date: 2026-05-11 | K & E Distributing👁️ views: 282added: 2026-05-07publication date: 2026-05-11 | | Sokolin👁️ views: 7261 | Barnes Solicitors LLP👁️ views: 7182 | Witt UK Group👁️ views: 8181 | | Valley Plating Inc👁️ views: 8198 | Dock Pros👁️ views: 8179 | Kivells👁️ views: 8149 | | Specflue👁️ views: 8136 | Weber Kracht & Chellew👁️ views: 8180 | Lucky Look👁️ views: 8285 |
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

