CISA, the ACSC, and the FBI say that the Play ransomware gang, active since June 2022, had breached ~900 organizations as of May 2025, up 3x since October 2023
In an update to a joint advisory with CISA and the Australian Cyber Security Centre, the FBI said that the Play ransomware gang …
Context & Ripple Effects
The disclosure extends a run of joint CISA-FBI warnings about ransomware operations: in February, the agencies said Ghost ransomware had reached victims across sectors and more than 70 countries. Earlier coverage also documented the FBI and CISA publishing tactics tied to Scattered Spider's collaboration with BlackCat.
Play's reported victim total matters because it turns an individual gang advisory into evidence of sustained operational scale, rather than a short-lived burst of activity.
First-order effects
- Organizations that may match Play's known victim profile face a more urgent need to review exposure and apply the mitigations in the updated joint advisory.
- CISA, the ACSC, and the FBI gain a clearer basis to prioritize victim notification, indicator sharing, and defensive guidance around Play activity.
Second-order effects
- Security teams and managed-service providers are likely to treat Play as a standing ransomware risk alongside other active groups, increasing demand for threat monitoring and incident-response readiness.
- The advisory model puts pressure on ransomware operators to change observable tactics once defenders operationalize the agencies' shared intelligence.
Third-order effects
- If repeated joint advisories continue to document large victim counts, ransomware defense will increasingly depend on cross-border public-private intelligence distribution rather than organizations acting on isolated alerts.
- The pattern points to ransomware becoming a persistent ecosystem-security problem: the key differentiator will be how quickly shared warnings are converted into controls across suppliers and customers.
The trend: Rising reported victim counts and recurring multi-agency advisories reflect the shift toward coordinated ecosystem cyber defense against durable ransomware operations.