
PLAY ransomware group, which recently targeted Britain’s largest car dealer Arnold Clark, is demanding that the dealer group pay a multi-million-pound ransom in cryptocurrency or else face a massive upload of leaked private and corporate customers’ data to the dark web
According to sources, the threat actors have already leaked 15 gigabytes of customer information such as National Insurance numbers, passports, addresses, copies of bank statements, and car finance documents on the dark web, and now they are threatening to post another 467 gigabytes of sensitive customer information, which is believed to be more than 30 times bigger than the first upload.
The company claimed in a Tweet on January 3 to have protected customer data after discovering suspicious traffic on its network on December Christmas eve. However, it did not confirm the nature of the attack.
According to Arnold Clark, the attack temporarily disrupted our business and, regrettably, our customers. Arnold Clark apologized for any inconvenience it may have caused. Uncertainty surrounds the incident’s full effect on business operations.
The company’s external security partners are currently performing an extensive review of its whole IT network and infrastructure and guiding the IT team on re-enabling their network and systems safely and securely, reports said.
Notably, Arnold Clark was one of many high-profile companies targeted by the PLAY group in December. Others include the Belgian city of Antwerp and cloud computing giant Rackspace.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543