Ransomware victim disclosure
← All victimsColtrane Systems
Claimed by Play · listed 15 hours ago
Status timeline
- ListedAug 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Play
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Aug 18, 2026
About the victim
AI dossier — public-source company profileColtrane Systems is an electrical and technology systems integrator offering design/build services across audio-visual, security, electrical, and infrastructure cabling. Operating from offices in St. Louis, Philadelphia, and Kansas City, they serve commercial, enterprise, industrial, healthcare, government, and utility sectors throughout the United States and internationally.
- Industry
- Electrical & Technology Systems Integration
- Address
- Multiple locations: St. Louis, Philadelphia, Kansas City, United States
Attack summary
Severity: medium — Data has been published by the threat actor (disclosed_status = data_published), but the leak post excerpt is minimal and provides no specifics about data type, volume, or sensitivity. Coltrane's client base includes government and healthcare, which raises baseline concern, but without evidence of what was actually exfiltrated, severity cannot be elevated higher.The 'play' group claims an attack on Coltrane Systems and has published data. No details are provided in the truncated leak post regarding whether encryption, exfiltration, or both occurred, or what specific data is at stake.
What the group claims
United States
Sources
Source
Indexed 15 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

