Ransomware Group Claims MyPillow Hack; Lindell Denies Breach and Calls It Political

A Russian-language ransomware operation called Play claimed in May 2026 that it hacked MyPillow, the Minnesota-based home goods company run by Mike Lindell, posting on its dark-web leak site that it had stolen private and personal confidential data, client documents, budget records, payroll, IDs, taxes, and other financial information. Play reportedly set a Friday deadline for MyPillow to make contact before publishing the stolen data online.

Lindell denied the breach, telling Straight Arrow News — which first reported the ransomware claims — that his company had not been hacked. “This is another hit job by outside sources because I’m running for governor,” Lindell said. “I guarantee it. We do not have any breaches in our data at all.” Lindell is among at least 10 Republicans seeking the party’s nomination for governor of Minnesota in August’s primary and is a prominent backer of Donald Trump’s false claims of victory in the 2020 election.

Play has affected more than 900 organizations since 2022. The group’s claim against MyPillow follows a broader shift in ransomware tactics: most criminal hacking groups now focus on stealing data and extorting companies rather than locking computer systems with malware.

In a separate development, the FBI warned this week that one ransomware group, the Silent Ransom Group, has taken that aggression further by sending people physically into company offices to steal data. Targeting law firms, the group’s operatives insert external hard drives or USB drives directly into victims’ computers to exfiltrate data — a tactic the FBI said has not been seen before. Researchers believe the group may be using freelancers who are unaware of who they are working for.

Also this week, AI surveillance company BusPatrol announced in 2026 that it will convert cameras installed in tens of thousands of U.S. school buses into automatic license plate readers, recording the location of every vehicle the buses pass and making that data available to law enforcement without a warrant — a significant expansion beyond the technology’s original purpose of ticketing drivers who illegally pass stopped school buses.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top