Security News This Week: Cybercrime Crew Claims It Hacked Mike Lindell’s MyPillow
Play ransomware claimed it stole MyPillow data; Mike Lindell denied any breach and called it a political hit job.
Intelligence analysis by GPT-5.4 Mini

WIRED says a ransomware crew posted claims about MyPillow data theft, while Lindell denied any breach. The item sits inside a weekly security roundup that also tracks AI-enabled crime, in-person data theft, and surveillance tech.
A hacker group said it broke into MyPillow and stole company papers. Those papers were said to include things like payroll and tax files.
Mike Lindell said that did not happen. He said the claim was really a political attack because he is running for governor.
Think of it like someone leaving a note that says, “I took your homework, pay me,” even before a teacher checks the desk. The note can still cause trouble, even if the story is not proven yet.
Analysis
What the claim is
WIRED reports that Play, a Russian-language ransomware operation, posted on its dark-web leak site claiming it had taken private company records from MyPillow. The alleged haul included customer and employee-related material such as documents, budget information, payroll records, IDs, taxes, and other financial files.
The response
The article says Play set a Friday deadline for MyPillow to make contact before publishing the data. Lindell told Straight Arrow News, which first reported the claim, that the company was not hacked. He framed the allegation as a political attack tied to his run for governor of Minnesota and insisted there were no breaches in the company’s data.
Why WIRED included it
This item appears in WIRED’s weekly security roundup, alongside stories about a ransomware group that the FBI says is sending people into offices to steal data in person, and about BusPatrol turning school-bus cameras into license-plate readers for police. Taken together, the roundup points to a security landscape where extortion is getting more aggressive, more physical, and more entangled with politics and surveillance.
The MyPillow claim is important, but it remains a claim in the article as presented. WIRED does not present independent confirmation of the breach in this section; instead, it contrasts the leak-site allegation with Lindell’s denial. That matters because ransomware crews often use public pressure, deadlines, and leak threats to force a response before victims can fully assess what happened.
The piece also places Lindell in a larger political context. He is described as one of the Republicans seeking the Minnesota governor nomination, and the article notes his prior defamation rulings over false 2020 election claims. That background helps explain why any alleged attack on his company could quickly become more than a routine security incident.
Key points
- Play ransomware claimed it stole private and financial records from MyPillow.
- The group reportedly gave MyPillow a deadline before it would publish the data.
- Lindell denied any breach and called the allegation a political hit job.
- WIRED placed the claim inside a broader weekly roundup about security and privacy.
- The story reflects how ransomware extortion often relies on public pressure and leak threats.



