discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

MyPillow appears on Play ransomware leak site

Play ransomware claims it hit MyPillow and threatens to leak data by Friday unless the company pays.

By Jessica Lyons·May 26·theregister.com·2 min read

Intelligence analysis by GPT-5.4 Mini

MyPillow appears on Play ransomware leak site
Image: theregister.com

Play ransomware operators have listed MyPillow on their leak site and say they stole confidential business and personal data. The company had not responded at publication time.

Why it matters

This is another example of ransomware crews pressuring a U.S. company by threatening public data leaks. It also shows how extortion groups continue to target businesses with broad claims about stolen payroll, tax, and finance records.

A cyber gang says it got into MyPillow's computers and took private files. It is threatening to put those files online unless the company pays money.

This is a bit like a bully saying, "Give me cash or I will spill your secrets." The secrets could include worker records, tax papers, and money papers.

The company has not answered yet, so the claim is not confirmed in the story. The bigger lesson is that computer thieves often try to scare companies by setting a deadline and threatening embarrassment.

Analysis

What happened

Play ransomware extortionists listed MyPillow on their leak site on Monday, according to The Register and a post shared by threat-intel firm FalconFeeds. The gang says it stole data from the bedding company and will leak it by Friday if MyPillow does not pay.

The post does not say how much data was allegedly taken, but it claims the haul includes "private and personal confidential data, client documents, budget, payroll, IDs, taxes, finance information" and more. MyPillow did not immediately respond to The Register's questions, so the article does not confirm the intrusion independently.

Why the story matters

The case fits a familiar ransomware pattern: criminals name a target publicly, attach a deadline, and list the kinds of records they say they have stolen to raise pressure. If true, the alleged exposure would matter because the claimed data set includes payroll, identity, tax, and finance records, all of which can create legal, operational, and personal risk.

The article also puts the threat in context by pointing to Play's wider track record. The Register notes that the FBI said in May 2025 that Play operators had allegedly exploited about 900 organizations. It also cites earlier incidents involving the Swiss government, Microchip Technology, and reporting from Cisco Talos that Play was among the crews using so-called "EDR killers" to disable endpoint security tools. The piece frames MyPillow as another alleged victim in a ransomware group that remains active and disruptive.

Key points

  • Play ransomware listed MyPillow on its leak site and demanded payment.
  • The gang claims it stole confidential business and personal data, including payroll and tax records.
  • MyPillow had not responded to The Register's inquiry at the time of publication.
  • The article places Play in a wider pattern of ransomware attacks on governments and companies.
  • The story is an extortion claim, not a confirmed breach disclosure from MyPillow.

Originally reported at

theregister.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityransomwarecyber-crimebusiness

Author

Jessica Lyons

Intelligence analysis by

GPT-5.4 Mini

Published

May 26, 2026

Source

theregister.com

Share

Topics

securityransomwarecyber-crimebusiness

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…