Ransomware victim disclosure
← All victimsTPIS Industrial Services
Claimed by Play · listed 3 months ago
Status timeline
- ListedMar 26, 2026
- Data leakeddate unknown
At a glance
- Group
- Play
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Mar 26, 2026
About the victim
AI dossier — public-source company profileTPIS Industrial Services is a family-owned and operated industrial services company headquartered in Pasadena, Texas, with an additional office in Decatur, Alabama. The company provides scaffolding, insulation, painting and sandblasting, dry ice blasting, electric and steam heat trace systems, refractory work, and safety training to industrial clients. It operates on a 24/7 basis and serves customers across Texas and Alabama.
- Industry
- Industrial Services & Maintenance (Scaffolding, Insulation, Coatings)
- Address
- 5121 Oak Ave, Pasadena, Texas 77503 (Texas Office); 853 Old Trinity Rd, Decatur, Alabama 35601 (Alabama Office)
Attack summary
Severity: high — The disclosure status is 'data_published', meaning the group has followed through on publishing stolen data. While no regulated medical or government data is indicated, a confirmed data publication from a business with employee PII, client contracts, and operational records constitutes a high-severity incident.The Play ransomware group claims to have attacked TPIS Industrial Services and lists the disclosure status as 'data_published', indicating that exfiltrated data has been released on their leak site. No specific data volume or ransom amount was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Business records
- Employee data
- Client/project information
- Internal communications
- Safety and training documentation
What the group claims
United States
The leak post
captured from the group's site| Play ransomware HAS NEVER PROVIDED AND DOES NOT PROVIDE THE RaaS, read the FAQ page.WE NEVER WRITES FIRST, IF SOMEONE WRITES TO YOU, THEY ARE SCAMMERS.we'll buy your access: 75tkvxemb6zpyk3fbl3mwm32jklc2sdjacb3kazrioamopbfn2w2z5qd.onionIf we have not responded to you by email within 12 hours, please leave your contact information on the website in the contact tab. | | --- | | EMA Engineering & Consulting👁️ views: 321added: 2026-05-07publication date: 2026-05-11 | Accessoires Outillage Ltee👁️ views: 280added: 2026-05-07publication date: 2026-05-11 | K & E Distributing👁️ views: 282added: 2026-05-07publication date: 2026-05-11 | | Sokolin👁️ views: 7261 | Barnes Solicitors LLP👁️ views: 7182 | Witt UK Group👁️ views: 8181 | | Valley Plating Inc👁️ views: 8198 | Dock Pros👁️ views: 8179 | Kivells👁️ views: 8149 | | Specflue👁️ views: 8136 | Weber Kracht & Chellew👁️ views: 8180 | Lucky Look👁️ views: 8285 |
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

