Ransomware victim disclosure
← All victimsRed Star Oil
Claimed by Play · listed 4 days ago
Status timeline
- ListedSep 9, 2026
Current state: Listed for ransom
At a glance
- Group
- Play
- Status
- Listed for ransom
- Listed on leak site
- Sep 9, 2026
About the victim
AI dossier — public-source company profileRed Star Oil is an oil and gas company. No further details are available from public sources or the leak post.
- Industry
- Oil & Gas Distribution
Attack summary
Severity: low — Red Star Oil is listed on the Play group's leak site, but the post excerpt contains only a listing table with view counts and publication dates. No proof files, data samples, attack details, or operational impact are stated. This appears to be a bare listing announcement without substantive evidence of data compromise or attack.The Play ransomware group has listed Red Star Oil on its leak site as of 2026-09-11. No specific details about the nature of the attack, data exfiltration, or encryption are provided in the available post excerpt.
The leak post
captured from the group's site| Play ransomware HAS NEVER PROVIDED AND DOES NOT PROVIDE THE RaaS, read the FAQ page.WE NEVER WRITES FIRST, IF SOMEONE WRITES TO YOU, THEY ARE SCAMMERS.If we have not responded to you by email within 12 hours, please leave your contact information on the website in the contact tab. | | --- | | GT Distributors👁️ views: 1537added: 2026-09-08publication date: 2026-09-11 | Red Star Oil👁️ views: 987added: 2026-09-08publication date: 2026-09-11 | Meteor Group👁️ views: 3249added: 2026-08-31 | | KRC Machine Tool Solutions👁️ views: 2439 | Figgins Family Wine Estates👁️ views: 2780 | MEQ👁️ views: 3062 | | Latoplast👁️ views: 5504added: 2026-08-20 | Woodhaven Association👁️ views: 5876added: 2026-08-17 | Marconi Industrial Services👁️ views: 7229added: 2026-08-09 | | Rilpa Enterprises👁️ views: 8043 | MIE Solutions👁️ views: 7367added: 2026-08-09 | Platinum Group👁️ views: 8427added: 2026-08-06 |
Screenshot of the leak post

Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

