Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

SOUTH-STAFFS-WATER.CO.UK

south-staffs-water.co.uk

Group Clop
Discovered 2022-12-22 20:02 UTC
Est. attack date 2022-12-22
Country GB
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

South Staffs Water - South Staffordshire Water

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 407

Third Party Employee Credentials: 1


External Attack Surface: 31


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • southstaffswater-co-uk01c1b.mail.protection.outlook.com. Microsoft 365
TXT Records
  • globalsign-domain-verification=312AC2040CBC0038E61773F7D89C3A01
  • d3lheqddvaj19ucdol1584vtod
  • 6bagoorqfgbeauem5lga2v0ttm
  • ht09isnmqkmg89fkbc8t1se1r7
  • F800-87C0-42EE-DC89-C3F1-0B78-8403-DD4C
  • globalsign-domain-verification=3DE8A7BC472B260463D77968454B2952
  • v=spf1 include:_u.south-staffs-water.co.uk._spf.dmarcld.com include:spf.protection.outlook.com ip4:168.245.25.91 include:_spf.salesforce.com include:spf.mailjet.com include:_spf.psm.knowbe4.com ~all
  • A75B-9112-337C-F596-8045-CFB2-C3EB-1959
  • globalsign-domain-verification=4DB4EB473B855767B05554D1820E1881
  • l6oqascmm4nun7rp3l5r60fcne
  • globalsign-domain-verification=705436BDBACF0C5FDE2B4862D0C2B061
  • google-site-verification=vz_Xmiets7OGDJmyxCNeAGORuH6XP_i-KNyxammB-3M
  • uq8787ll7r1o2fu40dc0l2egia
  • MS=ms35862600
  • hic5cn787cger35fbvl58gclr9
  • 8c4oifktgupoqia3iq431bsm72
  • 5oe36dgtsttrh3q96br3b9kss8
  • G0EwCdvU87M2uN7CqPZlULZs18JmN/0XuJElBRL5keWYfcRHt5ri/hAZr5J4vFvrIExITPHX1ViDu6Q68cNdRg==
  • 33WNC6TEH2XKUAWU6EVY7P6HYFG3RN5P
  • globalsign-domain-verification=7565A7A260B60D163C26E739B9D981C3
  • thdvo5vgp20q7r96joqgmuu08t
  • F220-7EF8-13DB-7BCE-7F7C-5E37-0BD1-170C
  • pb436bk7p12d78nsqju0llu9gn
  • tgvbsui2i9jpva07a88cp8p5o
  • globalsign-domain-verification=9IbmdYA9de-_vK2BO1oKgNXyrbtbOM6bKFyPXTVwGN
Cloud / SaaS Services Detected
KnowBe4 Mailjet Microsoft 365 Salesforce

Leak Screenshot:

Leak Screenshot