news.mlab.sh
Back to the feed
threat-intel

MyPillow listed on ransomware gang’s leak site, but denies it has been breached

High
Summary

The Play ransomware gang claims to have stolen data from MyPillow, a US pillow manufacturer, and threatens to release it publicly. MyPillow denies the breach and claims it doesn't hold sensitive data internally, relying on third-party providers. The situation highlights the risks associated with outsourcing data management and the potential for attackers to exploit vulnerable supply chains.

The alleged breach centers around the Play ransomware gang’s claim of possessing data from MyPillow, including client documents, financial information, and employee IDs. This claim surfaced on the gang’s dark web portal, with a deadline set for Friday for a potential data release. However, MyPillow CEO Mike Lindell has vehemently denied the breach, attributing the claims to political motivations related to his gubernatorial campaign. Lindell’s denial is further complicated by his company’s reliance on external third-party providers for data storage and processing, a common practice among modern businesses. This reliance creates a significant attack surface for ransomware groups, who often target these suppliers to gain access to a wider range of data.

Read the full article at Graham Cluley