Skip to content

PLAY Ransomware Allegedly Claims U.S. Firm J&J Gaming

Ransomware // Leak-site intercept
RW-2026-0627-JJG Unverified
OPERATION PLAY PlayCrypt

Active since 2022 · ~1,200 known victims · double extortion · suspected Russia-linked

Victim organization

J&J Gaming

Assessment
SeverityMedium
ConfidenceLow

A U.S. amusement, arcade & attractions company added to the PLAY ransomware data-leak site. The actor claims theft of confidential corporate data and threatens to release it on the stated publication date. Volume and scope are unverified.

Telemetry
GroupPLAY
CountryUnited States flagUnited States
SectorAmusement / Attractions
Domainjjgaming.com
Data volumeUndisclosed
Listing views1,065
Added2026-06-27
Publication2026-07-01
Actor note

Private and personal confidential data, clients documents, budget, payroll, IDs, taxes, finance information and etc.

As posted on the leak site · reproduced verbatim · unverified
Auction listing
Auction listingOpen
Current price-- BTC
06Days: 13Hrs: 23Min: 07Sec
Place bid
Preview
Redacted Open image PLAY ransomware leak-site listing preview for J&J Gaming, redacted
Assessment

Appearance on an active leak site indicates the actor claims to hold exfiltrated data and is using a publication deadline as leverage under a double-extortion model. The named categories - payroll, IDs, tax and finance records, and client documents - would, if authentic, expose the organization and named individuals to fraud, identity theft, and targeted extortion, with risk of public release rising sharply once the date passes. No data, samples, or actor contact channels are reproduced here, and the volume and scope remain unverified. J&J Gaming has not publicly addressed the claim as of this post.

Want the non-redacted screenshots? Paid subscribers get full claim details and unredacted screenshots. Find this alert on the ransomware feed after subscribing. View pricing

Dark Web InformerThreat Intelligence

Latest