Group:
Blackbasta
Discovered by ransomware.live: 2024-12-04
Estimated attack date:
2024-10-24
Country:
Description:
Graham + Sibbald is one of the UK’s leading property consultancy services. Our success is built upon how we deliver our service; it is a unique combination of being both professional and personable. Graham + Sibbald has a long-standing history of supporting and delivering community benefits. This ranges from offering work placements/shadowing experiences for secondary school children across our office network, working in partnership with local schools by surveyor participation and attendance at career fairs/ STEM practical workshops to supporting Modern and Graduate Apprentices through our dedicated Career Programmes.SITE: www.g-s.co.uk Address : 3 Charlotte Street, Perth Perthshire, PH1 5LW United KingdomTEL#: +44 1738 445733ALL DATA SIZE: ≈1.5tb 1. Personal documents Employees 2. Personal documents Clients 3. Financial data 4. Users data 5. Another Corporate data & etc…
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 1
Third Party Employee Credentials: 0
External Attack Surface:
1
DNS Records:
The following DNS records were found for the victim's domain.
- eu-smtp-inbound-1.mimecast.com.
- eu-smtp-inbound-2.mimecast.com.
- google-site-verification=CEcNxl5jyqZUJeebx3qbdhZc8ZSNLeyljzmEOIFPYoY
- 0ed1fe018a3e799677d0ad48e49590c1b2dd63897c
- v=spf1 include:eu._netblocks.mimecast.com ip4:212.20.252.246/29 ip4:195.89.173.22/30 ip4:212.84.180.234 ip4:84.22.176.153 ip4:92.71.135.178 include:spf.mandrillapp.com include:mailgun.org include:asp-spf1.yardi.com include:asp-spf2.yardi.com include:spf.x" "ledger.net ~all
- apple-domain-verification=CfVi9pDXA0nKFIzp
- google-site-verification=9UksDFN-3q3F6iJObVrj2lmfTmZzFFdlvKWBM6iYOKU
Cloud / SaaS Services Detected
Apple
Mailgun
Mandrill
Mimecast
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.