Quick Summary
AllegedExecutive Summary
Svensk Direktreklam, a business services company based in Sweden, has been identified as a victim on the Play ransomware group’s dark web portal. The listing, published on July 16, 2026, was detected by SOCRadar’s Dark Web Monitoring service. Operating within the Business Services sector, Svensk Direktreklam’s inclusion on the leak site places it within the context of Play’s recent targeting activities, which have spanned numerous regions and industries. The nature of Svensk Direktreklam’s operations, as a provider of business services, potentially makes it an attractive target for ransomware operations seeking to disrupt or extort organizations that play a key role in other business processes. In the 60 days leading up to this listing, the Play ransomware group claimed 17 other victims. Their recent activity shows a clear preference for targeting the Business Services, Telecommunication, and Construction sectors. Geographically, the group’s victims are predominantly located in the United States, the Netherlands, and the United Kingdom. Svensk Direktreklam’s profile as a Swedish business services company aligns with the Play group’s established targeting patterns. Notable recent victims that share a similar profile or industry include Mundt and Associates, Andorra Life, AG Scholtes, and Wring Group.
Technical Analysis
Initial access correlation utilizing SOCRadar’s stealer-log telemetry revealed a significant credential exposure for the sdr.se domain. The queried dataset returned 25 credentials associated with the organization’s primary domain and a distribution portal subdomain. These credentials were identified as covering external or partner accounts rather than internal employee logins for core systems. The predominant profile of these exposed credentials points to customer account takeover or supplier risk scenarios. The records are recent, with a freshness window of approximately one week as of July 2026. Importantly, no corporate email usernames were found within this specific data slice, which means the telemetry alone does not indicate a direct compromise of employee accounts. For ransomware actors like Play, credentials harvested by infostealers represent a well-documented pathway for initial access. Threat actors or initial access brokers often source fresh credential logs from underground marketplaces. They then validate these stolen credentials to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, subsequently deploying ransomware. While the stealer-log data observed does not definitively confirm that these specific credentials were used by the Play group to compromise Svensk Direktreklam, the pattern is highly consistent with the typical kill chain observed for such incidents. This exposure highlights the compromised accounts and associated endpoints as critical priorities for immediate credential rotation and thorough security review.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.