HIGHRansomware
Verified
Global
Play Ransomware Targets Managed Service Providers for Downstream Access
Monday, March 9, 2026 at 03:00 PM UTC·Source: CISA / MS-ISAC Advisory
Updated: Tuesday, March 10, 2026 at 11:00 AM UTC
Executive Summary
Play ransomware compromises three MSPs to deploy ransomware across 120+ downstream client organizations simultaneously.
Analysis
Play ransomware group compromised three managed service providers using FortiOS vulnerabilities, then used the MSPs remote management tools to deploy ransomware to over 120 client organizations. Downstream victims span healthcare, legal, accounting, and manufacturing sectors. CISA has issued specific guidance for MSPs on securing RMM tools.
Timeline
Discovered
Mar 5, 2026
Exploitation Detected
Mar 5, 2026
Published
Mar 9, 2026