Quick Summary
AllegedExecutive Summary
Latoplast, a manufacturing company based in Latvia, has been identified as a victim by the Play ransomware group. The company was listed on the group’s dark web portal on August 20, 2026, a discovery made through SOCRadar’s Dark Web Monitoring service. Operating within the plastics manufacturing sector and serving industrial and commercial clients in the Baltic region, Latoplast’s listing places it among recent European manufacturing targets of the Play ransomware group. This incident highlights the ongoing threat to industrial entities in the region. In the 60 days leading up to this listing, the Play ransomware group claimed a total of 28 victims. Their targeting has notably focused on the Manufacturing, Financial Services, and Technology sectors, with a significant concentration of victims in the United States, the United Kingdom, and Latvia. Other manufacturing companies recently targeted by Play include Marconi Industrial Services, Platinum Group, Sigma Plastics Group, and AG Scholtes. Latoplast’s geographical location in Latvia aligns with Play’s documented activity in the Baltic region, further emphasizing the group’s pattern of targeting companies within this area.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed one credential record associated with the latoplast.com domain. This record pertained to an external user account from a third-party organization, identified as a Canadian industrial supplier, which had accessed Latoplast’s web infrastructure. This type of access is consistent with portals used for customer or supplier interactions rather than direct employee compromise. While this finding represents a limited exposure and does not confirm internal credential compromise, credentials obtained through third-party access to supplier portals can potentially serve as an initial entry point for threat actors. For ransomware operations like those conducted by the Play group, harvested credentials from infostealers are a known vector for initial access. Threat actors or initial access brokers often procure these logs from underground marketplaces, validate the corporate credentials, and use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The single external-user credential identified in this instance does not definitively confirm its use as an initial access vector for Play. Crucially, internal employee credentials, which would provide a stronger indicator of pre-breach activity, were not found within the queried data. Security teams should therefore consider investigating access permissions related to third-party supplier portals as part of their incident response and risk assessment.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.