Group:
Clop
Discovered by ransomware.live: 2025-11-21
Estimated attack date:
2025-11-21
Country:
Description:
[AI generated] Humana Inc. is a leading US-based health insurance company, founded in 1961. Its coverage extends across the country, providing a range of insurance products and health and wellness services. These include medical, dental, and vision insurance, along with pharmacy services and health information technology solutions. Humana largely focuses on senior citizens, especially those enrolled in Medicare. The company is keen on fostering healthy habits and promoting preventive care efforts.
Infostealer activity detected by HudsonRock
Compromised Employees: 74
Compromised Users: 6972
Third Party Employee Credentials: 139
External Attack Surface:
121
DNS Records:
The following DNS records were found for the victim's domain.
- abusecomplaints@markmonitor.com
- whoisrequest@markmonitor.com
- mxa-00496301.gslb.pphosted.com.
- mxb-00496301.gslb.pphosted.com.
- onetrust-domain-verification=3284ec94a1154bc3848e61cbd096cd2f
- dropbox-domain-verification=6d1q156pkzkh
- facebook-domain-verification=inq9f2tzwqcl99hjorqifvpy8d55fz
- mongodb-site-verification=hQw02Mp6s2D8dSztUuYFL9VFrBo219OB
- amazonses:JSzakwmnT/jCUFM7rJ9bllYyI40w9L4fmsNqEm80Jug=
- google-site-verification=zSxrBb9WqUkJhb2y4r8J5G7jp2seRWasJenS74znlFU
- Dynatrace-site-verification=ae83e88d-07d5-40b9-b908-f51d5cf55113__70smgsf2a3fso4ukg84ouino17
- vmware-cloud-verification-7b989b88-79fb-4fa4-a09f-9b3946490753
- PzHUpXxDORNVWoO6/0JO9j7ZU4FxtRzy+74F3aua8/BazdJVg3ujXk4CmIsbczUSZ8g/XhTLgYPcziUt8YahlQ==
- onetrust-domain-verification=61d025aa26b9481881e0710be1843a26
- adobe-idp-site-verification=3cb86be2-909c-4b1a-8b16-42949b5b1b39
- ahrefs-site-verification_1b28cc1703a32b253c6bc921cf7cfc57f57eab4fdb32013cc7b7852aa27a0687
- onx=e8e99e4b-c12b-45e4-a45d-97b01353d907
- onx=5d425e8d-0469-4e56-9341-7274d4065f8a
- MS=ms88681392
- onx=5742cf93-fe75-4362-90f1-c6668dd5c0df
- onx=d8d8b28a-9abe-4289-9316-8af843dcad37
- intersight=f0f5fea21cd68ba40c567f81349ce917ba8b6db62d2c4eb8d1dea71698aec6b7
- onetrust-domain-verification=c8a0d909db9a45d0891c402496703277
- google-site-verification=axLPNsiCiBzkDLxvIp59E1Fm85DVtkC0BZee0shwSXM
- amazonses:ebMGW7pKb5Fi553zmj4GKaYqbXWTGpUAoQbu69zrNZc=
- apple-domain-verification=dqq9zPCRuOiKKNIQ
- jetbrains-domain-verification=48z4uyynm5vzzr1qfc3vg67rm
- google-site-verification=jqdS6-Y2qapPu5zmpAarOI5LZ7IqRSBAkPTindwsMLE
- docker-verification=f3880919-eb20-483d-b051-ef1347da5439
- v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
- k2zjm90vd8qr1p338bk4zxnyjx9wzdq7
- jamf-site-verification=t0EKIKs0ICX2AAwQf1KINw
- onetrust-domain-verification=b535d5054aa74c46a51eac792d125d8a
- xuJjzmsOnIdVBSgj2Q6L4pLY-Uo
- ciscocidomainverification=4d4f35fd0656bc1d0f8bd4baeee7ed109d2b9675343cf13ca2fe716c2c6f97d9
- postman-domain-verification=c08cbbcf7f6d5c4897da74ef84c640c19edc9ec4ec6886e13d03edc7645d243d4d630a614f776b4d2a4a85bd1dd30bd64b982d96d88b203aff4d775f13c215d1
- duo_sso_verification=ntKNfDdVJei8KDrVP96Ly3bVqgMjv6xy2cY5ZibIKrEliLMVTrphd7lBvSnSVSmv
- google-site-verification=0m9v1aDXY_2fPxZ4aM686id8BJUZuICt8hFEK8Mlm7Y
- adobe-sign-verification=22ccf7c28cbd046e0cc08985a3f0bd0
Cloud / SaaS Services Detected
Adobe
Apple
Amazon SES/WorkMail
Dropbox
Microsoft 365
Box
JamF
OneTrust
Cisco Duo
Proofpoint
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.