HIGHRansomware
Verified
Global

Play Ransomware Targets Managed Service Providers for Downstream Access

Monday, March 9, 2026 at 03:00 PM UTC·Source: CISA / MS-ISAC Advisory

Updated: Tuesday, March 10, 2026 at 11:00 AM UTC

Executive Summary

Play ransomware compromises three MSPs to deploy ransomware across 120+ downstream client organizations simultaneously.

Analysis

Play ransomware group compromised three managed service providers using FortiOS vulnerabilities, then used the MSPs remote management tools to deploy ransomware to over 120 client organizations. Downstream victims span healthcare, legal, accounting, and manufacturing sectors. CISA has issued specific guidance for MSPs on securing RMM tools.

Timeline

Discovered
Mar 5, 2026
Exploitation Detected
Mar 5, 2026
Published
Mar 9, 2026
Source Attribution

Originally published by CISA / MS-ISAC Advisory on Mar 9, 2026. Verified by: CISA, MS-ISAC.

Related Threats