Discovered
2026-04-08 15:26 UTC
Est. attack date
2026-03-23
Country
Sector
Agriculture and Food Production
Education
Energy & Utilities
Financial Services
Government & Defense
Healthcare
Hospitality
Manufacturing
Other
Professional Services
Retail & E-Commerce
Technology
Transportation
Description:
Adaptavist Group LTD is a British platinum Atlassian partner and enterprise software developer serving Fortune 500 clients including NASA, Visa, Deutsche Bank, and government organizations. The company's flagship product is ScriptRunner for Atlassian Jira, Confluence, and Bitbucket.
Complete infrastructure compromise: source code of all products (ScriptRunner, Salable licensing platform), 484,220 customer records from HubSpot CRM (GDPR violation), 20,000+ legal tickets with 33,000 documents including 2,000 NDAs and contracts, 3TB+ from Nexus repositories (production secrets, Docker images, Helm charts), Kubernetes, OAuth credentials, Snowflake Data Warehouse, Confluence (24,547 pages, 100+GB documentation), production databases. Licensing system compromised enabling product cloning.
Infostealer activity detected by HudsonRock
Compromised Employees: 1
Compromised Users: 48
Third Party Employee Credentials: 2
External Attack Surface:
34
DNS Records:
The following DNS records were found for the victim's domain.
- 7ad28971b9811f2752d1b1af15fdbdb15c25becb48f9fa970c073407112fe931adaptavist.com.whoisproxy.org
- trustandsafetysupport.aws.com
- 7ad28971b9811f2752d1b1af15fdbdb1b8f35b4b3e6186937cf18df30d01806fadaptavist.com.whoisproxy.org
- 7ad28971b9811f2752d1b1af15fdbdb1d1b68e88d04d0e88d8cd2e7904700341adaptavist.com.whoisproxy.org
- 7ad28971b9811f2752d1b1af15fdbdb11d89ebac74fd5c5b3dea6996e4d01fe1adaptavist.com.whoisproxy.org
-
alt2.aspmx.l.google.com.
Google Workspace
-
aspmx2.googlemail.com.
Google Workspace
-
aspmx3.googlemail.com.
Google Workspace
-
aspmx.l.google.com.
Google Workspace
-
alt1.aspmx.l.google.com.
Google Workspace
- count-okta-JdSYKWY06wJ1oic7XRIKM
- atlassian-domain-verification=0H/De//zzdpDQ6vqjcTlwaAle/YQdoWNmByHp1p9BjtCtEayKehFDIP4mEM/OSJW
- cloudflare_dashboard_sso=1305a335693cb3238c101edb22221801
- google-site-verification=DIGyGOMHdjelXZP7ddJXbpE8gWX6iVgu6WRFN-GjOyo
- MS=ms64578630
- atlassian-sending-domain-verification=43a140f1-b7e3-46e7-9c56-405d60512aba
- v=spf1 a:avms-prod-mail1.adaptavist.cloud a:eu-relay1.adaptavist.com a:na-relay1.adaptavist.com a:relay.openair.com include:455061.spf10.hubspotemail.net include:_spf.google.com include:shops.shopify.com ~all
- 123-reg-verification=tjuiekih277n8nbfbios98f417
- loom-verification=2623388275
- atlassian-domain-verification=/s42lzK6bCVPWdeaCtqTlBkd5uclasKUBxCy6pb0ACluKKpCW54oaJdaraCDhuDW
- atlassian-domain-verification=EL0T/mUusPJ2O35Nj41ss/gfVldvxi1LISP23s8J390fSifaPq35UMyrWwMiKar9
- docker-verification=461fdb98-187d-43ce-8086-49066918951a
- atlassian-domain-verification=DEefhVFsTuEG99+Qr7AAec-TFqTLz7tD5US8hm1te32xFZXEY8y8yH0VLdqXh/kT
- google-site-verification=ERtkPy1B4zNuUBuI5nytuokQW60yP6sHds_FhKDo0JY
- g7j9lgqfu5jjdmrgqtt8ecncp9
- google-site-verification=zPkkue5X3SF31WI5Y8hn0F9iv5MrZxIQuO9CvmaBYC4
- amazonses:u3b/GxEA6bGm5ZhACvoG04BdtKTx43YJNY1SL/PfoR4=
- google-site-verification=pDZKF8M0CR2m5v-cjnpPUiAiVysgYKotI8f4Pui32sc
- hibp-verify=dweb_38pa29rxhn02qvln3i6mbv6v
- google-site-verification=XaqlwK7XdQT3SuARVAL4-8bT1gN-4nxeSvMSXc70aVE
- google-site-verification=uI5AoLJOsoawwi4MMUYsOPbvkdoJoEsHtO1XOSEcsb8
- canva-site-verification=Obmm-RUwBAg-ta0L2ZWkxg
- hubspot-domain-verification=NzUzZDAyNDktN2U3My00MTA1LTk5NjMtZDNlMzIwZWRiNzU1
- apple-domain-verification=sKc4WuDUDLCKhLPT
- google-site-verification=2o0nJVRrHcFlSYpKw4JOdK5MmAOUQLIFY7nP1KjHMtM
- miro-verification=c2658feb237be8366c47b5fd6df703a5735e7278
- facebook-domain-verification=feo3t5flmrxod5gvu97qluvy97813s
- amazonses:90zDB36XJ/H7f9BWWhr1yW2E4PY5PILukn9jI/N+Mz8=
- hcp-domain-verification=8e0f7f4be27df4d1a422379185301184bc252d05d59ae12fd00a49c62f7e8264
Cloud / SaaS Services Detected
Amazon SES/WorkMail
Apple
Atlassian
Canva
Docker
HubSpot
Microsoft 365
Miro
Shopify
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.