Ransomware victim disclosure
← All victimsSokolin
Claimed by Play · listed 3 months ago
Status timeline
- ListedMay 7, 2026
Current state: Listed for ransom
At a glance
- Group
- Play
- Status
- Listed for ransom
- Listed on leak site
- May 7, 2026
About the victim
AI dossier — public-source company profileSokolin is a well-known fine wine and spirits merchant, historically based in the United States (Long Island/New York area), specialising in the retail and direct sales of premium and collectible wines. The company has operated for decades as a destination retailer and online wine merchant catering to collectors and connoisseurs. It is associated with the Sokolin family wine business heritage.
- Industry
- Fine Wine & Spirits Retail
Attack summary
Severity: low — The post is a bare listing with no proof files, no data size, no stated exfiltration, and no ransom demand — consistent with an initial announcement only.The Play ransomware group has listed Sokolin as a victim on their leak site. No ransom amount, data size, or explicit description of exfiltrated data has been stated in the post; only a listing entry is published at this stage.
The leak post
captured from the group's site| Play ransomware HAS NEVER PROVIDED AND DOES NOT PROVIDE THE RaaS, read the FAQ page.WE NEVER WRITES FIRST, IF SOMEONE WRITES TO YOU, THEY ARE SCAMMERS.we'll buy your access: 75tkvxemb6zpyk3fbl3mwm32jklc2sdjacb3kazrioamopbfn2w2z5qd.onionIf we have not responded to you by email within 12 hours, please leave your contact information on the website in the contact tab. | | --- | | EMA Engineering & Consulting👁️ views: 97added: 2026-05-07publication date: 2026-05-11 | Accessoires Outillage Ltee👁️ views: 61added: 2026-05-07publication date: 2026-05-11 | K & E Distributing👁️ views: 68added: 2026-05-07publication date: 2026-05-11 | | Sokolin👁️ views: 7058 | Barnes Solicitors LLP👁️ views: 6979 | Witt UK Group👁️ views: 7980 | | Valley Plating Inc👁️ views: 7995 | Dock Pros👁️ views: 7977 | Kivells👁️ views: 7944 | | Specflue👁️ views: 7933 | Weber Kracht & Chellew👁️ views: 7977 | Lucky Look👁️ views: 8078 |
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

