On December 27, 2022, the ransomware group known as Play added Furetank, Sirius Shipping, VAS, and Donsonet to its public leak site, listing the four Sweden-based maritime and logistics companies as victims of a ransomware attack in which internal files were allegedly exfiltrated.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Furetank
Get alerted the next time Furetank files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Furetank’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Leak Site
The primary disclosure on the Play ransomware leak site states that the four entities were compromised in a single incident and that attackers successfully exfiltrated internal files. The listing does not specify the exact number of records affected, the precise data types beyond “internal files,” or any ransom amount demanded. It simply states that data was taken and warns that samples will be published if the companies do not meet the group’s terms. The disclosure indicates the attack occurred prior to the December 27 publication date, but provides no technical details on the initial access vector or the specific systems compromised.
Why This Matters for You and Your Family
When companies in the shipping and logistics sector are breached, the information stolen often includes documents that contain names, addresses, dates of birth, national identification numbers, contact details, and sometimes financial records of customers, vendors, and employees. Even though the exact volume of exposed data remains unknown, any leak of internal files from a maritime operator increases the chance that your personal information may now be circulating among criminals. Sweden, EU residents are particularly exposed because these firms routinely handle crew lists, passenger manifests, freight contracts, and payroll data that tie directly to real identities. If your employer, shipping provider, or travel records connect to any of these four companies, your details may already be in the hands of extortionists.
The Doxxing and Identity-Chain Risks
Stolen internal files rarely stay isolated. Attackers routinely cross-reference leaked employee spreadsheets, customer databases, and operational documents with other breach data to build complete identity profiles. A single email or phone number found in these files can link your gaming username, social-media handles, and family members’ accounts into one continuous chain. This is exactly how credential leaks cascade into account takeovers that expose children’s gaming profiles, home addresses, and family photos. Once the chain is mapped, targeted doxxing, SIM-swapping, or spear-phishing becomes straightforward. The longer the data sits on a leak site, the higher the probability that multiple criminal groups have already downloaded and enriched the information.