AG Scholtes Data Breach

Alleged

Ransomware claim involving AG Scholtes.

Published: Jul 16, 2026 Play
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
AG Scholtes
Industry
Business Services
Threat Actor
Play
Date of Incident
Jul 16, 2026

Executive Summary

AG Scholtes, a manufacturing company based in the Netherlands, has been listed as a victim on the Play ransomware group’s dark web portal, with the listing published on July 16, 2026. This entry was identified by SOCRadar’s Dark Web Monitoring service. Operating within the Manufacturing sector, AG Scholtes becomes another organization featured on Play’s leak-site, reflecting the group’s recent and widespread activity across various regions and industries. The company’s operations in the Netherlands align with Play ransomware’s established targeting patterns. In the 60 days leading up to this listing, Play has claimed at least 17 other victims. The ransomware group shows a consistent preference for the Business Services, Telecommunication, and Construction sectors, and its victims are predominantly located in the United States, the Netherlands, and the United Kingdom. AG Scholtes’s profile as a manufacturing organization in the Netherlands fits within these observed patterns, similar to other recent victims such as De Waard Transport, Svensk Direktreklam, Andorra Life, and Wring Group.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry yielded no records for agscholtes.nl within the queried segment. It is important to note that a null result does not definitively confirm the absence of compromise. The query is based on a partial and paginated sample of data, and credentials can remain hidden through alternate corporate domains, personal email aliases, or logs that were harvested and subsequently rotated before they could be indexed. Therefore, the absence of credentials in this specific query for the domain agscholtes.nl should not be interpreted as evidence of no compromise. For threat actors like the Play ransomware group, infostealer-harvested credentials are a recognized method for initial access. Operators or initial access brokers often procure recent logs from underground marketplaces, validate the corporate credentials within them, and then use these to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, prior to deploying ransomware. The lack of evidence in the current query does not eliminate this possibility, as credentials may exist in data feeds beyond the scope of this investigation, might have been used and rotated before indexing, or could have been acquired under personal email aliases. Given these findings, CTI teams should continue monitoring dark web and stealer-log feeds for any related activity. Proactive verification of credential hygiene, including password rotation and multi-factor authentication reviews, remains crucial. Additionally, ongoing monitoring of alternate corporate domains and related Microsoft 365, VPN, and remote-access portal activity is recommended, rather than considering the null query result as a definitive sign of security.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.