// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
ColdRecon / Breach Radar / SentinelOne
Breach Record

SentinelOne

DISCLOSED 2026-10-03 · RANSOMWARE · RANSOMWARE

Play ransomware (PlayCrypt) gained access via a SonicWall VPN, moved laterally with Mimikatz and PsExec, exfiltrated data, and used the victim's own SentinelOne uninstallation utility to disable endpoint protection before encrypting systems. The incident highlights a double-extortion playbook and a specific method to bypass EDR by leveraging legitimate vendor tools.

The record

What we know

Disclosed
2026-10-03
Attack vector
Ransomware
RANSOMWARE
Sources

Cited reporting

Similar vector · recent

Other ransomware breaches on file

This page is the permanent ColdRecon entry for the SentinelOne disclosure. It updates if new public reporting emerges. All tracked breaches →

SentinelOne just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →