Group:
Clop
Discovered by ransomware.live: 2025-11-21
Estimated attack date:
2025-11-21
Country:
Description:
[AI generated] Grupo Bimbo is a Mexico-based multinational bakery product manufacturer. Founded in 1945, the company operates the largest baking company around the globe. It churns out over 13,000 products under more than 100 brands, including Bimbo, Sara Lee, and Thomas' English Muffins. Grupo Bimbo's products range across breads, cookies, cakes, among others, appealing to numerous market segments.
Infostealer activity detected by HudsonRock
Compromised Employees: 129
Compromised Users: 1270
Third Party Employee Credentials: 471
External Attack Surface:
47
DNS Records:
The following DNS records were found for the victim's domain.
- abusecomplaints@markmonitor.com
- whoisrequest@markmonitor.com
- webmaster@grupobimbo.com
- mxa-00032002.gslb.pphosted.com.
- mxb-00032002.gslb.pphosted.com.
- v=spf1 a include:spf.protection.outlook.com include:spf_c.oraclecloud.com include:spf-00032002.pphosted.com include:spf-00032003.pphosted.com ip4:4.31.132.132 ?all
- ms-domain-verification=f1acd365-dc24-461b-9f25-4dd51fe390cf
- _f5ozg2al0r8w8t60c5ehonjobftdpu6
- google-site-verification=JcZzKeKhOTWb83HQT4eZ-F_ArcsetZJ0AbehDqCXNDk
- sNdhGVhjR0qQQl21XLm1Ejl24+DumdI715kjDty8Qb9zIUyH9rKFaPw1qqgqk082egdDDmOXrdogszCE0446kA==
- MS=ms19287595
- MS=ms78104077
- atlassian-domain-verification=5atpRa5LhEFamMYe6kEHfWogRqL3vz8M/h8sU5MymRevKuazQ51pUgDjWUCnEsp8
- tmes=85f7941a33087660803405ae81623012
- google-site-verification=gkw3Nz-ZRPEjGCYP41pGSx0adwUrVFYe1pcXPdofkFk
Cloud / SaaS Services Detected
Atlassian
Microsoft 365
Oracle Cloud
TrendMicro
Proofpoint
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.