Quick Summary
AllegedExecutive Summary
Andorra Life, a healthcare organization operating in Andorra, has been prominently listed as a victim by the Play ransomware group. The claim, published on July 16, 2026, was identified via SOCRadar’s Dark Web Monitoring service. Operating within the Healthcare sector, Andorra Life’s inclusion in Play’s leak-site activity highlights the diverse range of entities targeted by this threat actor, extending beyond their traditionally most frequent targets. In the 60 days preceding this listing, Play had claimed 17 other victims, demonstrating significant recent operational tempo. The group’s typical victimology shows a concentration in Business Services, Telecommunication, and Construction sectors, with the United States, the Netherlands, and the United Kingdom being leading countries. Notable recent victims similar in profile to Andorra Life include Svensk Direktreklam, AG Scholtes, Wring Group, and Boston Electric and Telephone. Andorra Life’s listing, while somewhat outside the typical pattern, provides valuable insight into the expanding reach of the Play ransomware group’s operations.
Technical Analysis
Initial checks against SOCRadar’s stealer-log telemetry for the domain andorralife.com returned no matching records within the queried data slice. It is crucial to understand that a null result does not conclusively indicate the absence of a compromise. The nature of the query involves a partial, paginated sample, and credentials may exist under alternate corporate domains, be associated with personal email aliases, or have been harvested and subsequently rotated before their inclusion in the indexed logs. The absence of credentials for andorralife.com in this specific query signifies only that no such records were found in the analyzed data, not that the organization is unaffected. The Play ransomware group, like many others, frequently leverages credentials obtained through infostealer malware as a primary method for initial access. Threat actors or initial access brokers typically acquire recent credential logs from underground marketplaces, validate the authenticity of corporate accounts, and then utilize these credentials to gain entry into systems via Microsoft 365, VPNs, or remote access portals, ultimately leading to ransomware deployment. The lack of documented evidence in this query does not preclude such a scenario; credentials may have appeared in feeds outside the scope of this analysis, been rotated promptly after harvest, or used with personal email addresses not directly captured. Given the potential for compromised credentials to serve as an initial access vector, CTI teams should consider ongoing dark web monitoring and proactive credential hygiene checks as essential mitigation strategies. Cybersecurity professionals should not interpret a null query result as definitive proof of an organization being unaffected by potential compromise. Continuing to monitor alternate corporate domains, reviewing Microsoft 365 and VPN activity, and ensuring robust password rotation and multi-factor authentication implementation remain critical steps.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.