MyPillow appears on Play ransomware leak site
Play ransomware claims it hit MyPillow and threatens to leak data by Friday unless the company pays.
Intelligence analysis by GPT-5.4 Mini

Play ransomware operators have listed MyPillow on their leak site and say they stole confidential business and personal data. The company had not responded at publication time.
A cyber gang says it got into MyPillow's computers and took private files. It is threatening to put those files online unless the company pays money.
This is a bit like a bully saying, "Give me cash or I will spill your secrets." The secrets could include worker records, tax papers, and money papers.
The company has not answered yet, so the claim is not confirmed in the story. The bigger lesson is that computer thieves often try to scare companies by setting a deadline and threatening embarrassment.
Analysis
What happened
Play ransomware extortionists listed MyPillow on their leak site on Monday, according to The Register and a post shared by threat-intel firm FalconFeeds. The gang says it stole data from the bedding company and will leak it by Friday if MyPillow does not pay.
The post does not say how much data was allegedly taken, but it claims the haul includes "private and personal confidential data, client documents, budget, payroll, IDs, taxes, finance information" and more. MyPillow did not immediately respond to The Register's questions, so the article does not confirm the intrusion independently.
Why the story matters
The case fits a familiar ransomware pattern: criminals name a target publicly, attach a deadline, and list the kinds of records they say they have stolen to raise pressure. If true, the alleged exposure would matter because the claimed data set includes payroll, identity, tax, and finance records, all of which can create legal, operational, and personal risk.
The article also puts the threat in context by pointing to Play's wider track record. The Register notes that the FBI said in May 2025 that Play operators had allegedly exploited about 900 organizations. It also cites earlier incidents involving the Swiss government, Microchip Technology, and reporting from Cisco Talos that Play was among the crews using so-called "EDR killers" to disable endpoint security tools. The piece frames MyPillow as another alleged victim in a ransomware group that remains active and disruptive.
Key points
- Play ransomware listed MyPillow on its leak site and demanded payment.
- The gang claims it stole confidential business and personal data, including payroll and tax records.
- MyPillow had not responded to The Register's inquiry at the time of publication.
- The article places Play in a wider pattern of ransomware attacks on governments and companies.
- The story is an extortion claim, not a confirmed breach disclosure from MyPillow.



