Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Kering (Gucci, Balenciaga, Brioni, AlexMcQ)

kering.com

Discovered 2025-10-03 15:47 UTC
Est. attack date 2024-04-23
Country FR

Description:

[AI generated] Kering is a global luxury group that manages the development of renowned houses in fashion, such as Gucci, Balenciaga, Brioni, and Alexander McQueen. These brands are popular in clothing, leather goods, footwear, and accessories sector. Kering, based in Paris, France, empowers its brands to reach their potential in the most imaginative and sustainable manner.

Infostealer activity detected by HudsonRock

Compromised Employees: 12

Compromised Users: 122

Third Party Employee Credentials: 63


External Attack Surface: 37


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusenameshield.net
MX Records
  • mxb-00168301.gslb.pphosted.com. Proofpoint
  • mxa-00168301.gslb.pphosted.com. Proofpoint
TXT Records
  • autodesk-domain-verification=4oGsJDRUJf-YTdoyD65b
  • globalsign-domain-verification=50b8f2ee223ac9a29d85fefc9ad6cc5d
  • google-site-verification=ZCbdY5R-IqDExt_lWWp2oNlN7Eo0-NPKKDHwb4OgH_Q
  • apple-domain-verification=0HGA8uNWh8dgIawV
  • teamviewer-sso-verification=5218d21d0b0241439129c0a2413598b4
  • 7rzd3m15j7hjgmcx4svcskp9dhkhbhtn
  • atlassian-domain-verification=B57Bho3jb/Ctt7HOnilWnFYYRYEVNiIAyB7Hor9w72VhK/rDx4o8eljbQUAz5VJ3
  • wiz-domain-verification=0970542b8bdd53e884d9421c992824764f5552035a4c41d30c19d87fb05a83a2
  • NsrqB9F69X+U4+vapNWf90vjBfTDKZ1Mu7r6nx4h9r+ISqJPQUcIt0b03HV5UZfIidCPcwCIXLfDVRh3g2IvRw==
  • f39a35c8-5ea8-4a26-8781-cd0337c65279
  • f5dcac01233f4c3794f47b39f17715cc
  • gjktdh52r93scp1zqslmdytc75z26mw8
  • dell-technologies-domain-verification=kering.com_37e2af0f-9c3c-4cc4-8fe2-17db367afc66_1702852351
  • contractworksverify=2NDT468IxfNx1VvFYP3Xz
  • cisco-ci-domain-verification=9bc919d76650123749813e3ad47aa113cc86bbc6c6d310aa2d6606cda39a1b1
  • _4t1xsvj2lgs6lelt6h2nr94bgw0b1ho
  • apple-domain-verification=EPzADFBP7LFpiw5u
  • intersight=ef57c59b4fd6c5cf2248df1eff9e58a94ec79725de5ea01a7376ca49a84f81a2
  • globalsign-domain-verification=d6df4d7a7670c4e54465bddd06d930be
  • airtable-verification=17f537bc0b84958bac0a79a31244a552
  • cloudhealth=75239ef7-ed44-4ebc-bfb9-b745c0007680
  • atlassian-domain-verification=GmweJpnsa7TX6bHsWUBQkH87YmmtPYZ4Sms/NaGkBSATfFpLbd1SDfIkbd0xyoNl
  • onetrust-domain-verification=3bd0ede5aed44535aa93da157571cecb
  • Dynatrace-site-verification=39b63570-197d-4065-8fc5-c46d702d514d__cf89kjb9ep83ju32t4ofdo15b1
  • r8n61r5nv4x5mkr22rtph8q5339516qp
  • apple-domain-verification=Vw61PvMwyldQSl8D
  • amazonses:v3ZdJrTOnI61LG/R0u59fAK1Arp1W7H3knbVXvbXmkY=
  • MS=4AF174D09E1D51602EFECDC7400E8DC027016ABC
  • paloaltonetworks-site-verification=99bc3d0157df34270ce1d6faf011c8f611ac622a8b6e47ba57d9318f267707ff
  • airtable-verification=d5a35da7016b100292cfbc030238e89c
  • globalsign-domain-verification=99ba0e1e22f3148d63d6bd248a167ede
  • smartsheet-site-validation=dM5vJtqTnWdb1HwzzFIxj__ZC3gAiBO7
  • google-site-verification=VvWpRBvr2jkgde1kGk5j3xYoSB8zyrNbtXL5SkIrDFo
  • MS=ms30654300
  • adobe-sign-verification=c226b30a1477842c38a5433f3c1481e
  • OThtiVNY=b510bd6144478f1f755549502e9a6311
  • twilio-domain-verification=8392e4165f9da588bcd73a2964255997
  • globalsign-domain-verification=813D777B94CF78D08B28CAA4E9911FE3
  • adobe-idp-site-verification=4e285510eeb2b4d9085cb7a3a0433385b54ad26f335d1ff42a1215b859d78336
  • atlassian-domain-verification=79eeAhD/crvmu3sk/Vjarg1r7vJwMZatjLuZfiOSmlMHELd0BxjkwAcW0qKZws7t
  • amazonses:B/JONUS/MCkpBO0hH/qcHKGPQTI7qMz5aXUsh/76WlM=
  • contractworksverify=3pFuAm234K5eLe
  • v=spf1 ip4:3.123.151.205 ip4:3.66.57.96 ip4:13.111.87.4/28 ip4:34.241.179.243 ip4:50.31.57.204 ip4:52.51.23.160 ip4:64.73.120.224/27 ip4:85.233.200.164 ip4:91.207.212.22 ip4:93.174.64.138 ip4:167.89.110.192 ip4:167.89.126.180 ip4:180.87.182.9 ip4:185.132." "182.47 ip4:193.104.231.0/24 ip4:194.206.254.0/24 ip4:194.244.242.0/24 ip4:195.24.246.0/23 ip4:195.42.251.0/24 ip4:198.21.2.183 ip4:198.21.5.209 ip4:213.41.42.80/28 ip4:217.109.67.0/24 ip4:13.111.19.74 ip4:35.190.247.0/24 ip4:64.233.160.0/19 ip4:66.102.0.0" "/20 ip4:66.249.80.0/20 ip4:72.14.192.0/18 ip4:74.125.0.0/16 ip4:108.177.8.0/21 ip4:173.194.0.0/16 ip4:209.85.128.0/17 ip4:216.58.192.0/19 ip4:216.239.32.0/19 ip6:2001:4860:4000::/36 ip6:2404:6800:4000::/36 ip6:2607:f8b0:4000::/36 ip6:2800:3f0:4000::/36 ip" "6:2a00:1450:4000::/36 ip6:2c0f:fb50:4000::/36 ip4:172.217.0.0/19 ip4:172.217.32.0/20 ip4:172.217.128.0/19 ip4:172.217.160.0/20 ip4:172.217.192.0/19 ip4:172.253.56.0/21 ip4:172.253.112.0/20 ip4:108.177.96.0/19 ip4:35.191.0.0/16 ip4:130.211.0.0/22 ip4:51.25" "5.9.55 ip4:62.13.128.0/19 ip4:72.52.72.32/28 ip4:64.71.149.160/28 ip4:141.95.14.14 ip4:87.253.232.0/21 ip4:185.189.236.0/22 ip4:185.211.120.0/22 ip4:185.250.236.0/22 ip4:5.196.77.178 ip4:98.129.181.58 ip4:98.129.181.61 ip4:51.68.123.95 ip4:51.210.3.68 ip4" ":205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 ip4:142.215.34.172 ip4:142.215.34.174 ip4:67.192.208.248 ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149." "72.0.0/16 ip4:159.183.0.0/16 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 ip4:142.215.34.173 ip4:142.215.23.28 ip4:142.215.23.29 ip4:142.215.23.30 ip4:198.21.7.119 ip4:13.66.130.121 ip4:20.96.2.88 ip4:20.230.234.206 " "ip4:20.122.27.14 ip4:13.69.143.169 ip4:20.199.118.217 ip4:20.223.216.143 ip4:51.103.125.121 ip4:20.104.71.155 ip4:52.229.64.120 ip4:4.205.48.246 ip4:20.220.79.204 ip4:20.108.5.185 ip4:51.141.3.13 ip4:20.117.94.132 ip4:20.117.25.88 ip4:52.187.249.33 ip4:40" ".127.75.37 ip4:20.5.85.10 ip4:20.190.110.185 ip4:185.132.183.245 ip4:185.183.29.151 ip4:62.108.235.21 ip4:62.108.225.69 ip4:54.76.20.229 ip4:54.73.154.170 ip4:54.78.223.108 ip4:18.202.1.98 ip4:34.240.22.171 ip4:54.247.2.221 ip4:3.126.175.210 ip4:3.73.197." "77 ip4:147.78.32.80 include:spf.mandrillapp.com include:spf.protection.outlook.com include:_spf.salesforce.com include:_shortspf.launchmetrics.com include:amazonses.com include:_spf.zucchetti.com -all
  • pexip-ms-tenant-domain-verification=84951d0e-9d6a-4063-9f6f-f330bb37627f
  • _zj1yd6evyzmy9oa09q9yi09u2ggves6
  • shopify-verification-code=dE44RuWuzTiU2k2H61LAIHRXIeRmPe
  • bitrise-verification=df0128a1e37a5105-NFfBbWqI3MwY
  • teamviewer-sso-verification=30eded1fb5214856a37952d2fcffe7a2
  • apple-domain-verification=QT811iFuAH2gZZG8kUK6rz_1f-6lp42iSoi-pTpEgTI
  • SFMC-3KFyPZ7qoQeAvKDgzUXJkkE7ObfReMbUdROtNkcE
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce Teamviewer Autodesk Mandrill Cisco Twilio OneTrust Proofpoint

Leak Screenshot:

Leak Screenshot