Group:
Clop
Discovered by ransomware.live: 2026-01-25
Estimated attack date:
2026-01-25
Country:
Description:
[AI generated] TRUSTPAYMENTS.COM is a global payments company. They specialize in providing engaging and flexible payment solutions for businesses, ranging from startups to enterprises. They offer a range of services including online payment gateways, merchant accounts, risk & fraud management, payment processing, multi-currency processing, and more. Their aim is to assist businesses in reaching the global market securely and easily.
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 32
Third Party Employee Credentials: 1
External Attack Surface:
9
DNS Records:
The following DNS records were found for the victim's domain.
- trustpayments-com.mail.protection.outlook.com.
- abuseipdb-verification=NUmgJCPl
- access-domain-verification=b50a3ecc787a4bdca53e024bbd1a78f761761cbb94410dfc0fb732f4289733aa
- apple-domain-verification=F5GxC5KyGiDI4iE2
- atlassian-domain-verification=oJPkgaIg0llyoOQ0WXhakd4s7GDakpnKqeoZUwplmpBEu4aaaVVHLHr6RrSGg4JS
- bw=F4jyJwjzsJiLHL8wxglXBmgvGTqbBQMSoZBW3UXzOQ7s
- google-site-verification=4icqtrNIS93wFWSkb9aw2qicNlF_goJQUomfTdT-lU4
- google-site-verification=Tje-SG0bjGCMYHyuETwqB6SzL2-J4dllfcNHRFu-pmc
- mandrill_verify.Vgs_u5j4hH_aVWsahea2Jg
- miro-verification=e6d422aa6848aee55956c401da07d5247682836b
- onetrust-domain-verification=354accbcceab4fbb9619759622561f0dcloud
- v=spf1 include:spf.protection.outlook.com include:amazonses.com include:_spf.salesforce.com include:et._spf.pardot.com include:mail.zendesk.com include:spf.emailsignatures365.com include:spf.mandrillapp.com " "ip4:54.247.241.128/27 ip4:3.250.209.64/26 ip4:167.89.110.192 ip4:167.89.126.180 ip4:198.21.5.209 ip4:50.31.57.204 -all
- 00d20000000ckbfeas
- Foxit-domain-verification=707a5d5ea0a9d536da38f72925519542
Cloud / SaaS Services Detected
Apple
Atlassian
Amazon SES/WorkMail
Mailchimp
Salesforce
Zendesk
Miro
Mandrill
OneTrust
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.