All Choice Rentals Listed by play Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
All Choice Rentals was listed by the play ransomware group on June 26, 2025, after internal files were exfiltrated in a ransomware attack. Individuals who may have provided personal information to the company should check for notices or contact All Choice Rentals to determine whether their data was exposed.
People who have rented properties or done business with All Choice Rentals may now face uncertainty about whether their personal or financial details have been taken by criminals. Public reporting indicates that the Canadian company has been listed by the play ransomware group, which claims to have stolen internal files in a ransomware attack. With the number of people affected still unknown and the precise contents of those files unconfirmed, the practical stakes centre on the risk that private information could be misused for fraud, identity theft or other harm if the group's claims prove accurate.
The listing was reported on 26 June 2025. While details remain limited, the incident underscores how ransomware groups target organisations that hold customer and operational records, leaving ordinary people to assess their own exposure and take protective steps.
Breaking down the breach
According to available public information, All Choice Rentals was listed by the play ransomware group on or around 26 June 2025. The group claims that internal files were exfiltrated during a ransomware attack. No further Reported Details have been released about the timing of the intrusion, the method of access, the volume of data taken, or whether systems were encrypted. The number of people affected is unknown, and the organisation has not publicly confirmed or denied the claims at the time of reporting. Public detail is limited to the leak-site listing itself and the statement that internal files were involved. As with many such incidents, independent verification of the full scope is not yet available.
Inside play
Play is a ransomware group that has operated publicly since at least 2022 and is known for double-extortion tactics. In this model the group typically encrypts systems while also stealing data, then threatens to publish the material on its leak site unless a ransom is paid. The group has previously listed organisations across multiple sectors and countries, often posting sample files or directories to pressure victims. Its leak-site listings are claims made by the group itself and should be treated as unverified until corroborated by the affected organisation or independent investigation. In the case of All Choice Rentals, play has listed the company and asserted that internal files were exfiltrated; no additional specific statements by the group about this victim beyond that claim appear in the available facts.
About All Choice Rentals
All Choice Rentals is a Canadian organisation operating in the property-rental sector. Companies of this type typically manage residential or commercial leases, collect tenant applications, process payments and maintain records of occupants, guarantors and property details. Such businesses routinely hold names, contact information, identification documents, banking or payment data, employment and income details, and correspondence related to tenancies. A breach involving a rental firm is consequential because the data often combines identity documents with financial and residential history, information that can be valuable for fraudsters seeking to open accounts, apply for credit or impersonate individuals. The organisation’s Canadian base means any affected individuals are likely subject to Canadian privacy and consumer-protection frameworks, though the exact regulatory implications depend on the still-undisclosed scope of the incident.
The information in question
The only data type named in public reporting is “internal files” said to have been exfiltrated in the ransomware attack. No specific categories—such as customer records, employee files, financial documents or contracts—have been confirmed. Organisations in the rental sector commonly store tenant applications, leases, payment histories, government-issued identification, credit checks and internal operational documents. Because the exact contents remain unconfirmed, it is not possible to state with certainty which of these, if any, were taken. Readers should therefore treat the exposure of any particular data element as possible rather than established fact until further official disclosure occurs.
Why it matters
For individuals whose information may be among the internal files, the primary risks are identity theft, financial fraud and unsolicited contact. Stolen rental records can supply enough personal detail for criminals to attempt account takeovers, loan applications or phishing campaigns that appear legitimate because they reference real tenancy information. Even if only partial records were taken, the combination of name, address and other identifiers can enable further social-engineering attacks. For All Choice Rentals the incident raises operational, legal and reputational considerations, including potential notification duties under Canadian privacy law and the need to support affected parties. Because the number of people affected is unknown and the full data set is unconfirmed, the scale of these risks cannot yet be quantified, but the nature of the claimed theft means the possibility of harm is real and warrants caution.
What to do if you're exposed
If you have been a tenant, applicant or business contact of All Choice Rentals, begin by monitoring bank and credit-card statements for unfamiliar activity and consider placing a fraud alert with Canadian credit bureaus. Change passwords on any accounts that may have shared credentials or personal details with the company, and enable multi-factor authentication wherever available. Be alert to phishing emails or calls that reference rental history or personal information. Keep records of any suspicious contact. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets; such a scan provides an additional early-warning signal while official details continue to emerge.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
RGR Sportswear Listed by play Ransomware GroupLifebreath Listed by play Ransomware GroupWeed Man Canada Listed by play Ransomware GroupPewarchuk CPA Listed by play Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the All Choice Rentals Listed by play Ransomware Group →
Publicly posted by play — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.