Group:
Cactus
Discovered by ransomware.live: 2025-03-12
Estimated attack date:
2025-02-09
Country:
Description:
<p>Tempel is a leading manufacturer of high-precision magnetic steel laminations for the motors, transformers, and generators used in the automotive, industrial and energy markets, and beyond.</p><p>Website: <a href="https://www.tempel.com/">https://www.tempel.com/</a></p><p>Revenue : $628.7M</p><p>Address: 5500 N Wolcott Ave, Chicago, Illinois, 60640, United States</p><p>Phone Number: (773) 250-8000</p><p><mark class="marker-yellow"><strong>Download link #1:</strong></mark> <a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/TEMPEL/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/TEMPEL/PROOF/</a></p><p><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/TEMPEL/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/TEMPEL/PROOF/</a></p><p><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Personal identifiable information, confidential engineering data, drawings, customers' and partners' information, financial documents, corporate correspondence, database exports and backups, etc.</p><p><img src="/uploads/1_da7c977929.png" alt="1.png"><img src="/uploads/2_825bfb5b84.png" alt="2.png"><img src="/uploads/3_5f7ea6e7ad.png" alt="3.png"><img src="/uploads/4_ffcf162e74.png" alt="4.png"><img src="/uploads/5_d761d48e73.png" alt="5.png"></p>
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- mxb-008b7301.gslb.pphosted.com.
- mxa-008b7301.gslb.pphosted.com.
- MS=ms69006748
- apple-domain-verification=KH0GcsdDlemrjuak
- onetrust-domain-verification=2a698cdc322547a4bd03bbec2ef33a73
- openai-domain-verification=dv-bmL0D3hAcEChYk53BBTyiin7
- S7cA9YwwP2yM7Wc1UNsGW9+5gzUvdfeSNGMygeqQCZsLZ52I/hWj2gptW0+i1iRUhuXChy7X+iaqI2qxOY96jQ==
- PttyVnbqO2c61r0HDcYZsylefbq2Ve9c7Bi5jpX8bAltoA6f2K65m4YizjeiJkYxIwdkMclGF230mr9f6Kb+EQ==
- v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
Cloud / SaaS Services Detected
Apple
Microsoft 365
OneTrust
Proofpoint
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.