LIVE · cybersecurity feed
Live wire
ransomware

MyPillow listed on ransomware gang’s leak site, but denies it has been breached

A notorious ransomware gang claims to have stolen MyPillow's private data, but CEO Mike Lindell calls it a politically motivated "hit job." With the countdown ticking toward a massive dark web leak, who is telling the truth? Read more in my

zeroday.news · 65d ago

The ransomware group known as Play is claiming to have exfiltrated data from the US-based pillow manufacturer MyPillow. The group posted on its dark web leak site that it had obtained private and personal confidential information. Play threatened to release an unspecified amount of this data on Friday, potentially exposing documents related to clients, budgets, payroll, identification, taxes, and financial information.

However, MyPillow's CEO, Mike Lindell, has refuted these claims, stating that the company has not experienced any security breach. Lindell, who is also a prominent supporter of former President Donald Trump and is seeking the Republican nomination for governor of Minnesota, told Straight Arrow News that he was unaware of any alleged attack until contacted by the press. He suggested that the accusations are politically motivated, calling it a "hit job" due to his gubernatorial campaign. Lindell asserted that MyPillow has no data breaches and does not store sensitive information internally, relying instead on third-party providers.

The veracity of Play's claims remains unconfirmed. MyPillow denies a breach, while the ransomware group insists otherwise. The situation is expected to become clearer by Friday, the deadline set by Play for an undeclared payment. If the data is not released after this deadline, it could indicate that the attackers do not possess MyPillow data or were compensated to withhold it.

Experts caution that a company's assertion of not holding sensitive data on its own systems does not negate the risk of a breach. Modern businesses frequently share customer records, payroll, and financial details with various third-party vendors, including payment processors, fulfillment partners, HR and payroll services, and cloud hosting providers. These external systems can also be targeted by attackers, as a single compromise can yield data from multiple organizations.

From the perspective of individuals whose data might be at risk, such as customers or employees, the distinction between a breach occurring on a company's own servers or those of a contractor is largely irrelevant. If personal information like names, addresses, payment details, or tax information appears on a ransomware leak site, the source of the compromise has minimal practical impact on the affected individuals. Outsourcing data storage and processing does not shield a business from reputational damage or lessen the severity of consequences for those whose data is exposed.

The outcome of Play's threat will likely be revealed by Friday. Ransomware groups typically target organizations they believe may be willing to pay, underscoring the need for robust security defenses across all businesses.

ransomwarebreach
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.