Group:
Alphv
Discovered by ransomware.live: 2024-01-24
Estimated attack date:
2024-01-24
Country:
Description:
BrightStar Care was founded over 20 years ago on the belief that the best care always goes the extra mile. And that’s why we do exactly that for every client, family and organization we serve across the nation. From personal care, therapy, care communities, medical staffing and more, we’re always there for those who need us, showing that next level care is the most important part of who we are. We call it A Higher Standard®.
Infostealer activity detected by HudsonRock
Compromised Employees: 2
Compromised Users: 69
Third Party Employee Credentials: 14
External Attack Surface:
22
DNS Records:
The following DNS records were found for the victim's domain.
- brightstarcare-com.mail.protection.outlook.com.
- google-site-verification=BOzAFvJ4yhLv4Ojz1W7qnR2qhi6C3kYmoOq90v2MA4g
- google-site-verification=uEx_bZHYRKwdP5bY4gQ0Cn9bUS3ufueomaO_2La2XO4
- have-i-been-pwned-verification=e1df355edb63e8b1faf77722bdabb50f
- hj-ownership=c!vRgK1k@iaJ
- v=spf1 ip4:23.24.130.237 ip4:23.24.130.238 ip4:50.194.76.73 ip4:173.15.105.78 ip4:167.89.12.85 ip4:184.186.225.121 ip4:107.211.64.212 ip4:67.197.213.101 ip4:73.74.21.228 ip4:64.141.173.84 ip4:65.140.55.186 ip4:24.181.108.122 ip4:47.205.81.227 ip4:173.167." "237.201 ip4:173.9.229.29 ip4:12.50.156.194 ip4:74.204.70.140 ip4:50.104.110.2 ip4:184.17.137.238 ip4:204.15.171.6 ip4:198.37.153.11 ip4:209.202.128.38 ip4:66.188.101.42 ip4:167.89.12.85 ip4:54.84.163.169 include:spf.protection.outlook.com include:_spf1.br" "ightstarcare.com -all
- zoho-verification=zb72413026.zmverify.zoho.com
- ahrefs-site-verification_c317f40b7fd2bb6d07287cc6f7db138d468efcaf5979e7643de17488647abc18
- apple-domain-verification=dPUIRpn2WCc72hGN
- cisco-ci-domain-verification=35ce27c3fc74662668e37099f75ae71de8f76d34f01d3affc189b55801b75761
Cloud / SaaS Services Detected
Apple
Zoho Campaigns
Cisco
Have I Been Pwned
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.