Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

NHS Scotland

nhs.scot

Discovered 2024-03-27 09:42 UTC
Est. attack date 2024-03-26
Country GB

Description:

3 terabytes of data will be published soon.NHSScotland currently employs approximately 140,000 staff who work across 14 territorial NHS Boards, seven Special NHS Boards and one public health...

Infostealer activity detected by HudsonRock

Compromised Employees: 8

Compromised Users: 1158

Third Party Employee Credentials: 111


External Attack Surface: 18


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusedotscot.net
  • abuseiomart.com
  • hostmastereasyspace.com
  • abuseeasyspace.com
MX Records
  • nhs-scot.mail.protection.outlook.com. Microsoft 365
TXT Records
  • atlassian-domain-verification=QYGZpxTnRbzXXDCcVk6ToGC46B3LufRY+X9kJ1Ns4uk5KQo+skW0hUwUylRaZLH8
  • duo_sso_verification=gCakK1jevNphX1mTLSv0t0hxwtkIHGoL8J22APqRnIFGAgpBhRmM6eusQV2gJlB7
  • MS=ms39737001
  • google-site-verification=hkEERlp-bDh7Ioge0eUMqBGOgaJHYN6e_PRI_y5sOzE
  • v=spf1 ip4:213.161.89.71 ip4:213.161.89.72 ip4:213.161.89.73 ip4:213.161.89.103 ip4:213.161.89.104 ip4:213.161.89.105 include:spf.protection.outlook.com -all
  • cisco-ci-domain-verification=133d346ee106f824b1f29c96b08fbebcd2fc69d6bafffd5de9affea8b0430980
  • plausible-sso-verification=147fa5b2-75a9-4696-8ee6-a054024feae8
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Cisco Cisco Duo

Leak Screenshot:

Leak Screenshot