Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Group Dark Project New Group
Discovered 2026-08-05 13:08 UTC
Est. attack date 2026-07-31
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation
This is an emerging group, so this claim should be treated with caution until independently verified.

Description:

About Leviton Founded in 1906 and headquartered in Melville, New York, Leviton is a privately held global provider of electrical wiring devices, data center connectivity solutions, and lighting energy management systems. A major cyber attack has resulted in the Leviton company losing control over its entire repository of sensitive data, totaling approximately 1.4 terabytes. The massive breach exposed a wide range of highly confidential information, including internal financial records, proprietary project schematics and working documents, as well as the personal data of employees. Additionally, a significant quantity of other unclassified but highly sensitive information was exfiltrated in the breach, painting a stark picture of a total system compromise.

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 549

Third Party Employee Credentials: 16


External Attack Surface: 103


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domains-abusecorsearch.com
  • infodomain-contact.org
MX Records
  • mxa-00061b03.gslb.pphosted.com. Proofpoint
TXT Records
  • fl7vimlu0t0ko9jl8vmadmrpq4
  • ud7ctn2tdp2dh96ln70n7cegbr
  • MS=ms61494171
  • dig _aemverification.dev.leviton.com -t txt
  • j9i2udc3hbhpkdfnk6c7o1l34m
  • logmein-verification-code=d4c59d1c-8914-4ba2-bdcf-deb46460938f
  • 519380cd3bc39f9ca291ef834c6eb9613cf6f9d7c010417324
  • dcv.digicert.com=_pk173wohkmji7vkia9rebfrvrw89uj0\226\128\139
  • d365mktkey=Ps7HR42eHPc1iHW5GJEz3DecaxWNFfiY46ow97aLC8cx
  • 4m3q1e87n2q9c55ebj83cvv5tt
  • ultvp47vfprd26ohn4rn50tp8e
  • ms-domain-verification=19ed0cf4-0c31-42ec-8b3e-4b09465125bb
  • spycloud-domain-verification=f89e999a-6167-4bf9-8521-c9e9caf9f08a
  • smartsheet-site-validation=q5X-BNIcDQaRMf9Hd6q6jh1HpvbACzvY
  • v=spf1 mx a ip4:209.123.84.0/24 ip4:129.159.98.105/32 ip4:129.80.40.98/32 ip4:52.70.248.144/32 ip4:213.201.211.128/28 ip4:107.20.210.250/32 include:spf-00061b03.pphosted.com include:spf.protection.outlook.com include:aspmx.pardot.com include:amazonses.com" " include:mail.zendesk.com include:31d00b.workshop-spf.net -all
  • msfpkey=5f0yax79xetjcpczex8c6dtp3
  • 48i2BzJ2rh5G7b5OjPJsD9l3m1DRb38MxXO8eHcAsiCd/ppgm79ATx7dwxjLClvCGn55AVR7jiU8Fz8ldCJ55g==
  • zapier-domain-verification-challenge=ff0cdd6d-9be3-40d2-a68a-062ee6606055
  • ZAC93769883
  • 1DNMOT20T0MNV36SVK7HPFBG5P
  • 2vbq8qm152hfbco588onjm8h12
  • 2me77vb2pbsep2jq25oijcgq4d
  • adobe-sign-verification=b53cb811f6bc826f6f999874d5213644
  • sending_domain48512=24a8697fa42b55134af481d60016aea4dd38e22415c451ccf534639a7a7250de
  • atlassian-domain-verification=TgMaP1M//qQXi8kADP8qG24gMKz2MeQYh4UrtLOUNcVY3MLF2wk6WnL7ASOPoR9C
  • atlassian-domain-verification=fsnzeP8ZW7M4TbVA15kSChg6hGyQae/Y3pFykbEn7bxhqhJRmXGY6kIVAiaYmeWZ
Cloud / SaaS Services Detected
Amazon SES/WorkMail Atlassian LogMeIn Microsoft 365 Proofpoint Smartsheet Zapier Zendesk

Leak Screenshot:

Leak Screenshot