Ransomware victim disclosure
← All victimsPreferred Financial Group
Claimed by Play · listed 4 days ago
Status timeline
- ListedAug 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Play
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Aug 4, 2026
About the victim
AI dossier — public-source company profilePreferred Financial Group, Inc. is a financial services firm based in San Ramon, California, operating since 1979. The company offers mortgage lending (including no-cost loan programs), real estate brokerage services, and insurance brokerage across multiple US states. They partner with various lenders and insurance carriers to serve clients.
- Industry
- Financial Services – Mortgages, Real Estate, Insurance Brokerage
- Address
- 11 Crow Canyon Court, Suite 100, San Ramon, CA 94583
- Founded
- 1979
Attack summary
Severity: high — Confirmed data publication by Play group targeting a regulated financial services firm handling sensitive customer PII (loan applicants, real estate clients, insurance holders). Financial services are critical infrastructure; exfiltration of client data at a mortgage/insurance broker represents significant regulatory and privacy exposure.The Play ransomware group claims an attack on Preferred Financial Group and has published data. No specific technical details, exfiltration confirmation, or encryption claims are provided in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Financial records
- Client information
- Loan application data
- Real estate transaction records
- Insurance policies or quotations
What the group claims
United States
Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

