Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

MACYS.COM

MACYS.COM

Group Clop
Discovered 2025-11-21 17:37 UTC
Est. attack date 2025-11-21
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

[AI generated] Macy's.com is the online platform of Macy’s, Inc., one of the premier retailers in the United States. The company offers a range of products such as clothing, accessories, home goods and more from popular brands. It also provides features like online shopping, delivery, returns and customer service. Macy's.com reintroduces the convenience and ease of shopping to the customer's fingertips.

Infostealer activity detected by HudsonRock

Compromised Employees: 46

Compromised Users: 30003

Third Party Employee Credentials: 52


External Attack Surface: 105


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mxb-0009cc01.gslb.pphosted.com. Proofpoint
  • mxa-0009cc01.gslb.pphosted.com. Proofpoint
TXT Records
  • Value = cisco-ci-domain-verification=1da236168126214530fd9bbd8b4f20dede17dbc4e85d7bba104b7e232289ebbb
  • atlassian-domain-verification=SUqM5OsJ3RepnWYwYrJ1QmUY1yFxGUBk26RtbPxvp93m4aH2M85VaX9VwUl9asgm
  • Dynatrace-site-verification=5d4bd67e-319d-44a4-9cd8-313950577e34__e1k39uja672gp7k508hov7jlc3
  • v=spf1 mx ip4:208.15.91.0/24 ip4:208.15.90.0/24 ip4:204.214.48.37 ip4:69.25.227.128/25 ip4:74.217.49.0/25 include:spf-0009cc01.pphosted.com include:mg-spf.greenhouse.io include:spf-a.rnmk.com include:spf.protection.outlook.com include:mailgun.org ~all
  • apple-domain-verification=icRQk9How8pN8hDg
  • google-site-verification=TYUtXtVkDiCMSc3enxnqX59CLTiDiyNbf1ju8704UA4
  • canva-site-verification=B-fhSpcI_i1L4iR4NTMx0g
  • google-site-verification=5db5db4h370L_xTGkZFWTt4DS37jD9MoMNfgbSv3Ht4
  • extensis-domain-verification=b6a9468c-7909-4925-8f04-d1107de68cfa
  • intersight=c16f14811be1608418c466dcd90c820f49606ddf06802d9924013c9cdf1dae94
  • heroku-domain-verification=kdnrhzqtkm4r0ragrwkowsrffoka5sy0xj18q829cu
  • onetrust-domain-verification=1eaecbc366724844b5a4c518a537ff16
  • mongodb-site-verification=NBCPowJ9SyFXv4N4PhpsHSuOEwqSrLXE
  • adobe-idp-site-verification=4e9c2f2bb4cf3e66ef521a195b9b488e69d330fed4b5fe80ac814669d7d9a5f0
  • google-site-verification=k6xLD0gGGFRcQ3I4CmtsnolfXf9nWVoX15vpV35yCDc
  • MS=ms42514781
  • 3R3unSHIaTa+sMJdJbguCAV82k24b51KSOBavkwB4XWsoHskXgEJepsQogYJJEJIQ7/aRZ0Sfylct+06Hn5Ifw==
  • google-site-verification=MdnAKx0GkplXggnt9YLd1TQM749yPjTYzl1h7qunc-A
  • hpe-greenlake-domain-verification=3965434554717a4b31467462346971694537676378665a4c413262646f315070
  • omnissa-connect-verification-d853f130-8638-4a0d-bc6a-d4c46312aa85
  • mk-org-sso-fd012d70-ee9a-4e99-890b-2a42706d1098
  • facebook-domain-verification=s7fgjz2obl9y1hphphdm036q3ga6v6
  • google-site-verification=KvU5y4HxLBHy0Wzr5TlpJzRTjToIThYQJx42gIOY6IM
  • box-domain-verification=98611f08b4ce3abd122895e6883fd760315d1feb5ea684d9f1f1c4da432018c0
  • autodesk-domain-verification=H1bZGea-auZWjRKqPWeP
  • jamf-site-verification=pVlXCseHAsSJHN-GtFWqtw
  • heroku-domain-verification=glbilejlzmvkvey7rlfla324kk/axtyvxjqy/roi
  • google-site-verification=59bL16t-JCtZIb-Getjc3eHeDJpeyCyZY-J2c106TZQ
Cloud / SaaS Services Detected
Adobe Apple Atlassian Autodesk Box Canva Cisco JamF Mailgun Microsoft 365 MondoDB OneTrust Proofpoint

Leak Screenshot:

Leak Screenshot