Group:
Incransom
Discovered by ransomware.live: 2024-05-11
Estimated attack date:
2024-05-11
Country:
Description:
After the first post on our blog, we contacted the NHS administration for a month by phone and email urging them to negotiate. In response, we received laughter and statements that they didn't care if we published.
Moreover, we contacted the cyber police and received rudeness from these law enforcement officers.
And now they're trying to present it like this:
Julie White, chief executive of NHS Dumfries and Galloway, said: “This is an utterly abhorrent criminal act by cyber criminals who had threatened to release more data”.
Infostealer activity detected by HudsonRock
Compromised Employees: 11
Compromised Users: 93
Third Party Employee Credentials: 3
External Attack Surface:
12
DNS Records:
The following DNS records were found for the victim's domain.
- england-nhs-uk.mail.protection.outlook.com.
- globalsign-domain-verification=1773A04C4D9A9505BF64287111E04DB9
- _globalsign-domain-verification=-3NnsWnpRchIvnDJFf4X47CdOLLRTz2CtHCRZgVudB
- globalsign-domain-verification=CD26131C84AAB963A02214073478C228
- globalsign-domain-verification=05F539D2527D3CBDA5E31306DAC21708
- globalsign-domain-verification=D8A808F8AF83642A1904D56F19414A02
- v=spf1 ip4:212.250.43.0/26 ip4:212.250.23.64/26 ip4:40.69.37.211 ip4:52.164.249.202 ip4:52.169.21.42 ip4:52.169.238.60 ip4:52.169.76.42 ip4:52.169.90.89 ip4:208.85.48.32 include:_spf.sigmatechnology.cloud include:spf.protection.outlook.com include:spf2.en" "gland.nhs.uk -all
- ZOOM_verify_u1LDSut_TpO38IFZCQvY7w
- apple-domain-verification=cD21DlUFvozbmqh0
- teamviewer-sso-verification=29f16873e970431fbf501124fc7b7df8
- globalsign-domain-verification=d113231605744546537a885921c40df4
- globalsign-domain-verification=32F98BF264466C55A24FAD43A8F9D5AE
- 15evvpthm7le0hpafj7gic10pr
- google-site-verification=uHeC5GkKkDp_FmN2pc3BH0B4YfWiRmolqtr1RMGSuZg
- EF3E-27A9-2312-1FF4-4069-941C-4362-4BF7
Cloud / SaaS Services Detected
Apple
Teamviewer
Zoom
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.