Group:
Clop
Discovered by ransomware.live: 2025-11-21
Estimated attack date:
2025-11-21
Country:
Description:
[AI generated] MAS Holdings is a leading manufacturer of intimate apparel, sportswear, performance wear and swimwear. Headquartered in Sri Lanka, it's one of the world's most recognized design-to-delivery solution providers in the apparel and fashion industry. MAS operates with a network of factories in 15 countries, employing over 99,000 people worldwide.
Infostealer activity detected by HudsonRock
Compromised Employees: 98
Compromised Users: 310
Third Party Employee Credentials: 365
External Attack Surface:
112
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- eu-smtp-inbound-1.mimecast.com.
- eu-smtp-inbound-2.mimecast.com.
- cQHgaapHla2eHBsBeNf4Cl9BPY7iO/d5iTIVrQkuiIBa7IGZNsw1haVhSl/I8oA+5rVnbbNNIq9PKgxI/Cqtcw==
- globalsign-domain-verification=257CCD35CC475B4BAF5D507885FDD56A
- HrVw/hWKPXVgbTQQufqZkLpI8QwWtcufElX5om7kTUuOjrDaiCaHDGiCZrBvvP8RqsQcTm8WiGSIUK69236Pcg==
- globalsign-domain-verification=2D8982A1044ECDA306050AA5EE9D3EF9
- globalsign-domain-verification=6e99b90f23c4812d2281b05bfc69ee02
- v=spf1 include:eu._netblocks.mimecast.com include:spf.protection.outlook.com -all
- uk1n1mn3f9tsj45hndooj5dvfg
- ERPSf6qu6E64emV8/6k0VJ1cQgxHmF4GoAAPbVM+g4yr8UF/v5SfMHzoYR0cT7KuntfaoIxkUhVdlP3E48nIEQ==
- globalsign-domain-verification=2B1DD30CBE69BE5C1645C87248259881
- MS=ms24461520
- atlassian-domain-verification=6/nfGPX1lkV0NvwqO9YXSlxbd8yDMml35JVyuEV17MTZ2GJ8ZcWTRBetML4UGBY4
- eomdq247jjm0c1ba81ukjcsreq
- globalsign-domain-verification=1B131FB7FC1BCE2FEE8ACEFB6E1BA64B
- KaM3l3QU4DR7Awl8ArhXyCEwlucoeci7zz7ZUjT74HOGPBaOiSFNtz8074ton+LYgh4EO2W97T57xHTu53pUlQ==
- globalsign-domain-verification=baa21d8e8587bd0c8ab9145a6374677d
- globalsign-domain-verification=305FE5353D2F3CC49DEA2F72C463AE97
- facebook-domain-verification=jvv2kjihh86mhvf0exbcuctliuilw3
- ECEB958260DB9F66386703EB658F851D
Cloud / SaaS Services Detected
Atlassian
Microsoft 365
Mimecast
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.