Sellars Absorbent Materials Listed by play Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Sellars Absorbent Materials was listed by the play ransomware group on October 28, 2025, following the exfiltration of internal files in a ransomware attack that affected an undisclosed number of people. Individuals should check whether their data was involved and take appropriate protective steps.
Sellars Absorbent Materials, a United States-based company, has been listed by the ransomware group known as play. The listing was reported on October 28, 2025. Public details remain limited: the number of people affected is unknown, and the only information given about the data is that internal files were allegedly exfiltrated in a ransomware attack.
This matters because ransomware groups often use such listings to pressure victims into paying, and any internal files taken can contain operational, employee or customer information that creates lasting risk even when exact contents stay undisclosed.
What happened
According to the available record, Sellars Absorbent Materials was listed by the play ransomware group on or around October 28, 2025. The report states that internal files were exfiltrated as part of a ransomware attack. No further Reported Details have been released about the timing of the intrusion, the method of access, the volume of data taken, or whether systems were encrypted. The number of individuals affected is listed as unknown. The incident is associated with the United States, consistent with the company’s location. Beyond the group’s listing and the brief description of exfiltrated internal files, public information is limited.
The group behind it: play
Play is a well-documented ransomware operation that has been active for several years. Like many modern ransomware groups, it typically follows a double-extortion model: it encrypts systems and also steals data, then threatens to publish the stolen material on a dedicated leak site if a ransom is not paid. The group has previously targeted organizations across manufacturing, professional services and other sectors, often claiming to have taken large volumes of internal documents. Its public leak site is used both to name victims and, in some cases, to release sample files as proof of the theft.
In this instance, the group claims to have listed Sellars Absorbent Materials and to have exfiltrated internal files. That listing itself is a claim made by the group; independent confirmation of the full scope of the intrusion or the precise contents of the files has not been provided in the public record. Play’s established pattern is to pressure victims through the threat of publication rather than through technical novelty alone.
About Sellars Absorbent Materials
Sellars Absorbent Materials operates in the industrial and commercial absorbent-products sector in the United States. Companies of this type manufacture and distribute materials used to control spills, manage industrial fluids and support workplace safety and environmental compliance. They typically maintain records related to manufacturing processes, supply-chain partners, employee information, customer accounts and regulatory documentation.
A breach at such an organization is consequential because the data held can include both operational details that competitors or other actors might exploit and personal or commercial information belonging to employees, customers and suppliers. Even when the exact files taken remain unconfirmed, the mere possibility that internal records left the company’s control creates ongoing risk for anyone whose information was stored in those systems.
What data was at risk
The only data type named in the available facts is “internal files exfiltrated in ransomware attack.” No further breakdown—such as employee records, customer lists, financial documents or technical specifications—has been disclosed. The number of people affected is unknown.
Organizations in the absorbent-materials and industrial-products sector commonly hold employee personnel files, payroll and benefits data, customer order histories, supplier contracts, quality-control records and internal operational documents. Because the public report does not confirm which of these categories, if any, were among the exfiltrated files, the exact contents remain unconfirmed. Readers should treat any specific claims about particular data types as unverified unless additional official statements appear.
The real-world impact
For individuals whose information may have been among the internal files, the practical risks include potential exposure of contact details, employment information or other personal data that could be used for phishing, identity fraud or social-engineering attempts. Because the scale and precise contents are unknown, the level of risk for any single person cannot yet be quantified.
For the organization itself, the incident can disrupt operations, require forensic investigation and remediation, and create longer-term concerns about trust with customers and partners. Even if systems were restored, the fact that files were taken means the data remains outside the company’s control and could surface later. The absence of confirmed numbers does not eliminate these risks; it simply means the full picture is still incomplete.
If your data was in this claimed breach
If you have a past or present relationship with Sellars Absorbent Materials—as an employee, customer, supplier or contractor—treat the possibility of exposure seriously even though exact details are limited. Monitor financial and email accounts for unusual activity, be cautious of unexpected messages that reference the company or request personal information, and consider placing fraud alerts with credit-reporting agencies if you believe sensitive personal data may have been involved. Change passwords on any accounts that reused credentials associated with the company, and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can help you identify other exposures that may require attention.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Stoughton Steel Listed by play Ransomware GroupJZ Russell Industries Listed by play Ransomware GroupUniversity Loft Listed by play Ransomware GroupRelease Marine Listed by play Ransomware GroupLatest breaches
Publicly posted by play — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.