Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

LV.COM

LV.COM

Group Clop
Discovered 2025-11-07 14:36 UTC
Est. attack date 2025-11-07
Country GB

Description:

[AI generated] LV.COM (Liverpool Victoria) is a UK-based insurance company offering a broad range of insurance and retirement products. The company provides services such as car, home, travel, life, and pet insurance, as well as investment and retirement plans. Known for its comprehensive cover, competitiveness and quality customer service, it's one of the largest insurance companies in the UK.

Infostealer activity detected by HudsonRock

Compromised Employees: 6

Compromised Users: 1142

Third Party Employee Credentials: 26


External Attack Surface: 101


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • eu-smtp-inbound-2.mimecast.com. Mimecast
  • eu-smtp-inbound-1.mimecast.com. Mimecast
TXT Records
  • MS=ms87289806
  • google-site-verification=Fub2hwElK2wyFt1Ll2MHxgeWpK_J3ZCJzbsQpi-DpdU
  • atlassian-domain-verification=T6vuOq5Mna0ntfrkUmaWD8EdJPtsGuoEv111SfKDWRU7tcMhW1HovG4/1A2lul2x
  • _xydu1ocn2kze5x0ecbjty7q77gcfrs2
  • o3ukojQjI0xcgU+8msAgRothbVyUuKxbtAgp7U1KR3B6sBLXefuJtLNn6Ojid8d+g46AXmHMmSmMOiO2uDqcrg==
  • parkable-domain-verification=T50v2_LP55xvD2o3MK8qkmU7MekPM_LQj3JcY_aZakI=
  • 8FB2-4AF2-11EA-6C09-3B2B-1C90-743E-38A0
  • docusign=a5db462b-ed57-4db0-9c8c-82d8b7829cf6
  • MS=ms22759385
  • have-i-been-pwned-verification=34fcaab44e32c82bc7514db8a5369400
  • canva-site-verification=mjgfqb3PVFCQsnkMnNICjA
  • _wh76iomhl6560kr29chd2n8ht6ds454
  • google-site-verification=sARFSMj5fIPWNpoaFZoiDKrhSR5dl1FHEfTq8w-jS8w
  • dropbox-domain-verification=smk0a7mmxt0u
  • MS=ms23727856
  • PaN6Bw2OXYrwdhomH81F5ezGH/dwvQRaIYYrRAmkjC61esygWm+dgI20GG8jTWS7eAtpK65evH5f+Ko5Byqw9g==
  • MS=ms19876212
  • google-site-verification=16J_e86sPEclrz1Igx5MGK4_P5hT13l5AQCEK_GNgn4
  • v=spf1 include:_netblocks.mimecast.com -all
  • atlassian-sending-domain-verification=51b4a302-93b5-40a1-8360-0e1b1716f390
Cloud / SaaS Services Detected
Atlassian Dropbox Microsoft 365 Box Mimecast DocuSign Have I Been Pwned

Leak Screenshot:

Leak Screenshot