Group:
Blackbasta
Discovered by ransomware.live: 2024-02-13
Estimated attack date:
2024-02-02
Country:
Description:
Global Rescue (a Global Rescue Company) has been a leader and pioneer in the travel services industry since our founding in 2004. We provide the finest integrated medical, security, travel risk and crisis management services available anywhere, delivered by our teams of critical care paramedics, physicians, nurses and military special operations veterans. Our medical advisory and evacuation services include exclusive relationships with the Johns Hopkins Department of Emergency Medicine Division of Special Operations, Elite Medical Group and Partners HealthCare. Our track record has made us the chosen provider to government agencies and some of the world’s largest companies, universities, nonprofits and tour operators. Our mission is simple – to be there when it matters most.SITE: www.globalrescue.com Address : 85 MECHANIC ST, LEBANON, NH 03766 USAALL DATA SIZE: ~155gb 1. Personal documents 2. Acct 3. Public 4. Legal 5. HCM and etc…
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 12
Third Party Employee Credentials: 1
External Attack Surface:
3
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- globalrescue-com.mail.protection.outlook.com.
- google-site-verification=dcVDJhha4YcMrSCDSo5mtfpDWRVceWF9zJqg7AkGuy4
- tpkvF2BCqo51WF3fLFFd/t9AqXYE8tiY83tJQY5/7rvI928JVxamHyxJaSOD9s8oGoR6x+4rxWzjkmmN3qcrWA==
- v=spf1 mx a ip4:52.5.181.10/32 ip4:52.20.149.239/32 include:spf.protection.outlook.com include:customers.clickdimensions.com include:_spf.messagegears.net include:amazonses.com ~all
- MS=ms59830286
- facebook-domain-verification=gt4cmkngc8gwxglpgm08dswrx1nqx3
Cloud / SaaS Services Detected
Amazon SES/WorkMail
Microsoft 365
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.