Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Accenture Breach Evidence & Debunking Rob Lee’s Lies

accenture.com

Discovered 2023-10-15 14:46 UTC
Est. attack date 2023-10-15

Description:

How ironic! Rob Lee, the outed threat actor, working under the guise of a seasoned cyber-security professional, recently tweeted the above, in an attempt to throw shade at the various claims made about him. In one such email exchange, Rob asks Dragos colleague Nanci Uher for her thoughts on using stolen data from the Accenture…

Infostealer activity detected by HudsonRock

Compromised Employees: 16269

Compromised Users: 35029

Third Party Employee Credentials: 3726


External Attack Surface: 200


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mx0a-001dcc01.pphosted.com. Proofpoint
  • mx0b-001dcc01.pphosted.com. Proofpoint
TXT Records
  • 4NvLLK5t7rBsujs4vl8VDloZ3mn8L7+67LBKEXUNPPQNlt5lMFpCo2+k2mcJL9EjheiMP3kHyZ+n2UtBLnUS3w==
  • hpe-greenlake-domain-verification=31584f6c626b69415855715435314b4d74475753437831627268786e58793147
  • mistral-domain-verification=2139895d79fff1a2ad175fa9bd924a7bedc186e5
  • segment-site-verification=KdumQotN1Pg0BHSGtL2rvgYKx0ghWAbf
  • adobe-sign-verification=da99fb7e471e8e812595bd6a8c5e2875
  • pardot1011361=d825a72fd69c0e25f7f62670660ae32a2701e0ee9d280ab006296ed11b058941
  • notion-domain-verification=gnhjuSDWpptmSxIQQ47C0Dp8nXcUME25kMxltXMAmii
  • docusign=614ac0a7-7549-4436-b0f7-d6465424f092
  • hcp-domain-verification=0e03260bb7505916bfd820706db91216a997647e5a18f72d6a27266a9047d835
  • nulab-verification-code=8TTNkc4cj170WuQDQXnntAFmVZulfy8muhpysoP7FuaDXfoObfZUYi5GfIFFO5OI
  • _7pi0npf3z4etnofxtbi3sbgo6wlb099
  • monday-com-verification=3bD2wbN66_PVrOmLpWA5FS75DF9RC47efxRHg1SkrbQ
  • atlassian-domain-verification=sM/6A7tL8dzMRpm1KrxPZYnCcXhQqiEJdDjgEfzq7Bjze1IkxLLSHLy92oeUBPsL
  • onetrust-domain-verification=317d4e96c02745d9a69ecde3a1772bd2
  • apple-domain-verification=UKTR9hD2CBdNapMPHWSIzNhZ76cyAi58RzKRNPjbsVc
  • cursor-domain-verification-wg5vby=7drCgtNfbsnpS3n3Z8WXx9RWl
  • figma-domain-verification=3e347c955c08b17b30e28103a9f755ce4f119f8936bea56b56d05cf609f88a4a-1745856596
  • 676294466-1012188982
  • mongodb-site-verification=cFVXO1EtlHjsZ0uCqBPAVB4DodFYh0wU
  • stripe-verification=558d0c1464f98248c5bc40f311e16e3119ebf71f40d426e5fed427acb0a8ddbf
  • remarkable-domain-verification=a3fa4bc4-194a-434b-93b0-26ad640d766b
  • smartsheet-site-validation=6WKcBZVtX1tBTc2dEsYpkswqp-BOFGHx
  • sending_domain1011361=d2c9d723c0cf979a75118da8b54e4c50a364825840c0e68d68b55e054be61935
  • Dynatrace-site-verification=6a1a0918-bfc7-4da4-a9ca-1c9d309705d8__ksfb72s1vpj8hcsdtn7779p8jp
  • Dynatrace-site-verification=cf509ddc-d5d6-43a1-a4c2-c120d3b0933b__v9qm0u1chpsc5jhkdpafn869s3
  • paloaltonetworks-site-verification=cb18840bf30df87d765413356307cf22e2b11b3a5fb5f389d828f108ce556d3d
  • unity-sso-verification=be147dd4-7167-4fa4-9cf6-96d0cd7e9e20
  • _6tame9aur5agkv0zdvub5b7w1x1jvwm
  • amazonses:8GzbTEmni2PBRv6jLZwAq1rcYGkbVEmlNuHIcahJ1K0=
  • bettercomp-verify=d4c92ff7f01512a34088ec632a21c697438ccc389e17e4c0ad4dfb386a74dc89
  • docusign=870c49f4-6731-4257-a7c8-4772d6d4dc41
  • twilio-domain-verification=5f1565b62c940a9ad638e3c7c088dc37
  • _q6j0ly9p7z4oygwn0yvvjxhmbyztzyl
  • pardot1011361=55d052b12751cad0eb2cc7eb9cbee111aed934ab445c2bcdd323bcf7591b8053
  • cisco-ci-domain-verification=757b62f6f592352dcec308d68d984e829ffc63970f7a52579405448c1f39b4f2
  • _qkllabfm40beybzwddjw021uy90xijb
  • onetrust-domain-verification=5322fc89fae740838eee535685a9fe46
  • facebook-domain-verification=9ydnlipioha0hvzv7f2wk44xgpu829
  • asv=c7a401fd2ce4afdc4c9898caee92a999
  • mixpanel-domain-verify=9603fa0a-c970-4b25-b616-021ec454bfa4
  • docker-verification=dddd690d-45c7-4cdc-b2b8-552178bab04e
  • adobe-idp-site-verification=228a2025-9a29-4a24-9dfd-4f0b7d1a9416
  • atlassian-domain-verification=59aeShSTbEvs7cB33k4Wsvath8fOirTAy79UnAbOloto0AyhJb41hHFK8SGb8zxF
  • atlassian-domain-verification=7KcyvCxeJOqBY5fwEHdp8/Nmk9RR7Am4Ihf65044gsFaDhwDtT3fmmt3gdGbur3M
  • v=spf1 include:_spfa.exchange.accenture.com include:_spfb.exchange.accenture.com -all
  • nulab-verification-code=k4l5aMXngpLUhKTLEuiHj2dDFSUBLxoKetjixslAkfHvvwcBagg14LmP9Ru4xUZO
  • clayton-domain-verification=b74f705c0b4e4369823f5e0717bdaba2abeb4b48d5
  • smartsheet-site-validation=UN0O6saeN0eC4nwqPk4iRmw7tplSKGNf
  • nulab-verification-code=po38DELk2wUybx9tqt8l1itaG14rCIRuK1FPGoEFPURa5fi1gF1rTQIxZefWdAfa
  • stripe-verification=BB11E45F6EB04F0F3639CBC7E7C56E9579F457BCC44999D1BC492F3C8E03BE4E
  • airtable-verification=e15163bb14cd2edb93b1ea662e99ca6b
  • 317d4e96c02745d9a69ecde3a1772bd2
  • smartsheet-site-validation=owIJ5MLqX9KoiMfKRnEcU_FVn3xQVPlA
  • cursor-domain-verification-j45q7n=TfB5WOfOYVsGgKv1dCP25KUzO
  • Hp48LTxGknu4omlcp1bP0HqFH2VBFOLA88QS7zwDTJQaM2moc6schoR8P30qVYcuO/RK+cUiCTnntk5pSUk+SA==
  • docusign=e1dd24c3-bc77-412d-ac0a-46a644d9a2db
  • segment-site-verification=61CRxasIWPOKQ18sWSJbXw47vFAiXou7
  • vvcdtvzwt07bq628pl7h6sy8bfkkc5cy
  • MS=ms19684732
  • stripe-verification=bd6f964c54e62df78d79def27c68a2b4af1c0fd24c5cfbd19097c8cb0e3819b4
  • figma-domain-verification=f7c08cd51dc05c2d7c362e60c65b5eb0df260db19719137f8f337c5c6a47c05c-1734592139
  • atlassian-domain-verification=sQQk6YxOzvD/debvDHjnRazCDNLZ3S0a0a50paa8T6CyuAb7ItKJmb47bFXKHv4f
  • atlassian-domain-verification=DIJvpa34BYkIAvV7ZxCb6IOGuU7vvIvop5U6m2j72w9/CqLgzWM9DmG/aJd0C5u7
  • anthropic-domain-verification-9vqrpf=ishzrUGD7nNGZwFmOqjkx20yQ
  • cursor-domain-verification-6terpc=DehnlvlE1od64vx2qGjyUz1to
  • globalsign-domain-verification=002EF26EDC67C8BF6CDBC8076E5B62EF
  • google-site-verification=ExtHh0dxqS8yolvzCzLiv6B96zJ-K6a2G1aZ1KUSg_U
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Docker Microsoft 365 Salesforce Stripe Anthropic Segment Cisco Twilio OneTrust DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot