Ransomware victim disclosure
← All victimsGCATS Investments
Claimed by Play · listed 3 hours ago
Status timeline
- ListedAug 10, 2026
Current state: Listed for ransom
At a glance
- Group
- Play
- Status
- Listed for ransom
- Listed on leak site
- Aug 10, 2026
About the victim
AI dossier — public-source company profileGCATS Investments is listed as a victim on the Play ransomware group's leak site. No public website or additional company information is available to verify operational details, scale, or business focus.
Attack summary
Severity: low — Entry is a bare listing on a ransomware leak site with no proof files, no data inventory disclosed, no ransom demand stated, and no operational impact described. Listing alone does not confirm a successful attack or data exfiltration.Play ransomware group claims to have compromised GCATS Investments and lists it on their leak site. No specific details regarding encryption, exfiltration, or data types are provided in the available post.
The leak post
captured from the group's site| Play ransomware HAS NEVER PROVIDED AND DOES NOT PROVIDE THE RaaS, read the FAQ page.WE NEVER WRITES FIRST, IF SOMEONE WRITES TO YOU, THEY ARE SCAMMERS.If we have not responded to you by email within 12 hours, please leave your contact information on the website in the contact tab. | | --- | | Marconi Industrial Services👁️ views: 685added: 2026-08-09publication date: 2026-08-12 | Rilpa Enterprises👁️ views: 1488added: 2026-08-09publication date: 2026-08-13 | MIE Solutions👁️ views: 830added: 2026-08-09publication date: 2026-08-13 | | Platinum Group👁️ views: 1916 | GCATS Investments👁️ views: 2013 | Signature Services👁️ views: 1918 | | Preferred Financial Group👁️ views: 2016 | First Tek👁️ views: 2036 | Cambridge Management👁️ views: 2494 | | Sigma Plastics Group👁️ views: 2683 | The Butcher Brothers👁️ views: 2594 | The DeBruler👁️ views: 3932added: 2026-07-25 |
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

