Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Aman Resorts (aman.com)

aman.com

Discovered 2026-04-19 18:07 UTC
Est. attack date 2026-04-18
Country SG

Description:

Over 500k Salesforce records containing PII have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 30

Third Party Employee Credentials: 81


External Attack Surface: 18


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • eu-smtp-inbound-1.mimecast.com. Mimecast
  • eu-smtp-inbound-2.mimecast.com. Mimecast
TXT Records
  • v=spf1 include:eu._netblocks.mimecast.com include:spf.protection.outlook.com include:_spf.peoplevine.net include:nextguest.app include:autotask.net include:_spf.salesforce.com ~all
  • 7h51j3ml2dr3d93cl72cc4zryq12k5rg
  • x4kb1wb9086qc75mvwy447tkbthgk971
  • 0ed1fe018a061bf093f83941918007b0392c3397f6
  • apple-domain-verification=LKPHflPrUzsXsHix
  • facebook-domain-verification=vgvfirf4ipx3pv35wholmkyextb1bq
  • smartsheet-site-validation=lGcGtCqA1IR4wcRVrJgtZEx0Y5dNU54z
  • onetrust-domain-verification=7a33296a5d0a4b2fbe65d40d91d1aaa6
  • _globalsign-domain-verification=6Vj5RE_9qAjlRUu7Gle37bpQndNq3qoCeMUOjS2Czv
  • S4jPXnjCN7sszeNXR1w4PX3El+cYXPIDKChYZBqRyfQWjcyupAJGNQGZQ2rbNo1OBDxq19DK6nN+da97eUAKgg==
  • cisco-ci-domain-verification=524fc13c9905c5b46432426400ba1e366811f0ab6e898a7575ff6255970c96d
Cloud / SaaS Services Detected
Apple Global Sign Salesforce Cisco OneTrust Mimecast