Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Poca Valley Bank

pocavalleybank.com

Group Storm
Discovered 2026-09-30 03:31 UTC
Est. attack date 2026-09-28
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Poca Valley Bank offers a range of tailored banking options including personal and business checking and savings accounts, loans, and advanced online banking services. The bank focuses on building relationships with its clients, providing customer education, and enhancing financial management through innovative solutions like mobile banking and cash management services. Their intended clients include individuals and businesses seeking reliable financial services in various locations. Poca Valley Bank is committed to security and customer satisfaction, ensuring a trustworthy banking experience. The company headquarters is located in 7033 Charleston Road, Walton, WV 25286, United States. 51-200 Employees

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 1


External Attack Surface: 1


Exposure Report
by ParanoidLab
155
Passwords
2 critical
0
Cookies
0 critical
Last queried 2026-09-30 06:44 UTC

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • pocavalleybank-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • Foxit-domain-verification=5c1722bbcd085fd4be5781dc6911d367
  • google-site-verification=LqLuP74ofY0ykXg3LreNiIxZYdsJq-4qMCUUOQA1OWA
  • pu9a53sndstmlbpv4qmm99kqoi
  • v=spf1 mx ip4:192.64.78.111/32 ip4:208.93.20.2/32 ip4:173.45.128.6/32 ip4:192.64.74.173/32 a:outbd-pstfx.customercenter.net a:outbd3-pstfx.customercenter.net ip4:66.76.197.27 include:spf.protection.outlook.com include:spf.cashedge.com exists:%{i}.spf.hc52" "15-40.iphmx.com ip4:23.90.99.167 ip4:139.138.34.27 ip4:207.144.71.87 ip4:162.210.14.20 ip4:207.144.71.98 ip4:208.66.22.33 ip4:44.214.246.148/32 ip4:167.89.15.50 ip4:198.37.156.10 ip4:64.187.116.194 include:_custspf.sageworks.com -all
  • MS=ms70275201
  • cisco-ci-domain-verification=44476a77d1342785646188e7f1ea68a16d62e6e9689edfbb0989c8e8fca549cc
Cloud / SaaS Services Detected
Cisco Microsoft 365

Leak Screenshot:

Leak Screenshot