Ransomware victim disclosure
← All victimsZuther Hautmann
Claimed by Play · listed 1 day ago
Status timeline
- Listed
May 20, 2026
Current state: Listed for ransom
At a glance
- Group
- Play
- Status
- Listed for ransom
- Listed on leak site
- May 20, 2026
About the victim
AI dossier — public-source company profileZuther Hautmann appears to be a company targeted by the Play ransomware group. No public website or additional identifying information was available to determine the nature of their business, location, or scale of operations.
Attack summary
Severity: medium — Play ransomware is a known double-extortion group that typically both encrypts and exfiltrates data. The listing with a scheduled publication date implies data is held and will be released, but no specific data types, volume, or proof files have been disclosed yet, warranting a medium rating pending further disclosure.The Play ransomware group has listed Zuther Hautmann as a victim with a publication date of 2026-05-24, indicating an impending or active data disclosure. No details on encryption, exfiltration, or specific data types were provided in the post.
The leak post
captured from the group's site| Play ransomware HAS NEVER PROVIDED AND DOES NOT PROVIDE THE RaaS, read the FAQ page.WE NEVER WRITES FIRST, IF SOMEONE WRITES TO YOU, THEY ARE SCAMMERS.If we have not responded to you by email within 12 hours, please leave your contact information on the website in the contact tab. | | --- | | Zuther Hautmann👁️ views: 203added: 2026-05-19publication date: 2026-05-24 | DURAND-WAYLAND👁️ views: 1292 | Ashcroft Homes👁️ views: 1328 | | IWC Food Service👁️ views: 1319 | ACC Construction👁️ views: 1314 | Northern Mechanical Contractors👁️ views: 1344 | | Town Car International👁️ views: 1308 | Infoworld Membership Systems👁️ views: 1350 | EMA Engineering & Consulting👁️ views: 1389 | | Accessoires Outillage Ltee👁️ views: 1319 | K & E Distributing👁️ views: 1322 | Sokolin👁️ views: 8253 |
Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
