Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Grupolider | Grupo Actual

grupolider-ao.com

Discovered 2026-07-10 12:57 UTC
Est. attack date 2026-07-10
Country AO
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

The leaked files will be available for download on May 10, 2026. Grupolider is a prominent Angolan conglomerate that has been operating in the national market since 1999. Headquartered in Catete, Luanda, the group initially started as a freight forwarding company and has since diversified into a wide range of sectors including agriculture, construction, and furniture. Grupo Actual is a human resources and recruitment agency in Portugal that provides temporary work solutions, permanent recruitment, and selection services.Following a rebranding in late 2025, the company formerly known as Leader now operates under the Actual brand.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4

Third Party Employee Credentials: 11


External Attack Surface: 3


FortiBleed Exposure Detected

This domain's FortiOS SSL-VPN credentials were exposed via the "FortiBleed" leak (CVE-2022-40684).


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • alt4.aspmx.l.google.com. Google Workspace
  • alt2.aspmx.l.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
  • alt3.aspmx.l.google.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
TXT Records
  • v=spf1 include:sendersrv.com ?all
  • v=spf1 a mx include:websitewelcome.com ~all
  • MS=32F884C5C448AEB966676405B49D85ED6035F5C2
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot