PenLink, a technology and surveillance software company, was reportedly impacted by a ransomware attack by the Play group, which was publicly claimed on February 22, 2026. The incident involved an extortion notice from the Play group, stating that sensitive data would be leaked if negotiations were not initiated. This information was reported via ransomware tracking sites and security researchers.
The specific types of data compromised and the total number of affected individuals have not been publicly detailed in available sources. Preliminary data from one source indicates the compromise of credentials for one employee and one third-party employee, but further specifics regarding data types or a broader scope of affected individuals remain unclear. The states affected by this incident have not been specified.
Details surrounding the PenLink data breach, including comprehensive breach notification letters, official company statements, or regulatory filings, have not yet been released. More information regarding the scope and impact of this incident may emerge as investigations progress.