Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

MESA Products

mesaproducts.com

Group Medusa
Discovered 2026-02-14 11:26 UTC
Est. attack date 2026-02-13
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

MESA Products is a U.S.-based industrial company that supplies cathodic protection materials and corrosion control solutions. The company focuses on preventing rust and structural damage in critical infrastructure such as pipelines and underground metal systems. Its product range includes test stations, connection kits, and monitoring equipment used to measure and maintain corrosion-protection systems. MESA emphasizes safety, reliable manufacturing, and high on-time delivery performance while supporting engineers, utilities, and construction sectors. The company’s mission is to protect people, property, and the environment by extending the life and reliability of essential infrastructure through quality protective technologies and technical support services. The company headquarters is located in 4445 S 74th East Ave, Tulsa, Oklahoma 74145, United States. 201-500 Employees

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 1


External Attack Surface: 2


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • us-smtp-inbound-1.mimecast.com. Mimecast
  • us-smtp-inbound-2.mimecast.com. Mimecast
TXT Records
  • zoho-verification=zb11678392.zmverify.zoho.com hosting
  • 430bn268mfh86c6p1gjsnfioiv
  • MS=ms75859052
  • bt39kikaeqh7n0vlcgrupc5gft
  • c7vf8h33viajt409bosjj8lvtn
  • google-site-verification=L_J7DtafzWJA2-r5nZd2SZIM3kW8cFpZCcgRmQh2mTo hosting
  • nbahossof28796rr3nvkhn4odg
  • 0ed1fe018aecf65bae98ca48c4a5fec2e5aa94e0cd
  • spycloud-domain-verification=bb29fe13-0b72-4a96-920d-c7b2502d2d25
  • v=spf1 ip4:67.214.99.125/32 ip4:216.16.132.2/32 ip4:162.208.45.41/32 ip4:75.99.133.234/32 ip4:74.92.50.85/32 ip4:63.157.89.10/32 ip4:24.180.76.30/32 ip4:50.231.11.106/32 ip4:184.189.107.211/32 ip4:12.94.88.218/32 ip4:72.67.47.186/32 ip4:207.98.154.46/32 i" "p4:96.65.213.201/32 ip4:12.129.29.143/32 ip4:198.37.147.129/32 ip4:54.212.0.142/32 ip4:44.238.213.166/32 ip4:54.71.123.73/32 ip4:24.204.51.49/32 include:spf.constantcontact.com include:relay.bswift.com include:spf.protection.outlook.com include:us._netblo" "cks.mimecast.com include:_spf.psm.knowbe4.com include:_spf.salesforce.com include:amazonses.com -all
Cloud / SaaS Services Detected
Amazon SES/WorkMail KnowBe4 Microsoft 365 Mimecast Salesforce Zoho Campaigns

Leak Screenshot:

Leak Screenshot