Kool-air, a Canadian company, was listed on the Play ransomware group's leak site on February 15, 2024. The extortion actors claim to have exfiltrated internal files during a ransomware attack. The leak-site listing does not specify how many individuals or records are affected, nor does it detail the exact data types beyond stating that internal files were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Kool-air
Get alerted the next time Kool-air files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Kool-air’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Play ransomware group's leak site states that Kool-air was compromised in a ransomware incident and that attackers successfully exfiltrated internal files. The disclosure, hosted on the onion address via ransomware.live, provides no victim count, no list of specific documents, and no breakdown of customer or employee data. It simply states the company as a target and indicates that files are held for extortion purposes. Public reporting on Play ransomware consistently describes this style of posting as the final stage of their double-extortion tactic: first encrypting systems, then threatening to publish stolen data unless a ransom is paid.
Why This Matters for You and Your Family
When a company that handles air-conditioning, refrigeration, or related services in Canada suffers a breach, your personal information may be exposed even if you never directly interacted with Kool-air. Internal files often contain customer contracts, payment records, service addresses, phone numbers, and email addresses. If your information appears in those files, it can be used for identity theft, phishing, or sold on underground markets. Your family members listed on joint accounts or shared service agreements face the same risk. The disclosure indicates the breach occurred before the February 15, 2024 listing, meaning data may already be circulating among criminals.
Doxxing and Identity-Chain Risks
Stolen internal files frequently link names, addresses, phone numbers, and email accounts. Attackers and downstream data thieves can chain these details with usernames found in other breaches, creating a complete profile that leads to doxxing. A single exposed email or phone number tied to your home address can unlock social-media accounts, online shopping profiles, and even children's gaming accounts that reuse credentials. Once one account falls, attackers pivot to reset passwords elsewhere, escalating from data theft to full identity takeover. This cascading effect turns a corporate breach into a personal nightmare that can affect every member of your household.