Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo CPS.EDU

Group: Clop

Discovered by ransomware.live: 2025-01-24

Estimated attack date: 2025-01-24

Country: US

Description:

[AI generated] CPS.EDU refers to Chicago Public Schools (CPS), one of the largest public school districts in the U.S., serving over 355,000 students in 642 schools. It provides comprehensive educational programs, including traditional, magnet, charter, and special education for students from preschool through high school. The district also offers programs for English language learners and special needs students. CPS is committed to improving public education and preparing students for their future.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 194

Compromised Users: 2724

Third Party Employee Credentials: 1574


External Attack Surface: 129



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • usb-smtp-inbound-1.mimecast.com.
  • usb-smtp-inbound-2.mimecast.com.
TXT Records
  • adobe-idp-site-verification=0f6ce28e3442488a0e3275fc5e6707980e66f8485928a917678a9a3edea2eb62
  • cisco-ci-domain-verification=2afeedffee74f590f3d4ad0a95128c8bce442aa6824bfb0e0d706b1765547ebf
  • docusign=fde12f64-7579-455b-b917-325a570cb9ca
  • sending_domain954043=a0ceb4f6e917798e0e812ae02babf2724be4c366419b63f6dd5cfa05b6c37f3a
  • MS=AF213F747950198B36CEB225645512C1FFAA7F97
  • e2ma-verification=t50bb
  • v=spf1 include:_g1.cps.edu a:b.spf.service-now.com include:_a.cps.edu include:_spf.bbnotify.net include:rp.oracleemaildelivery.com include:usb._netblocks.mimecast.com include:_spf.salesforce.com ~all
  • MS=ms48801062
  • google-site-verification=XfdQRzQLIGdOZCVQVWAzYpR2-4nJOmxZenEsTZ4xjlc
  • docusign=763ca110-98ab-4955-9c91-023f2157292e
  • airtable-verification=7cd312f2fa2f45b985fadcd983c9f2ea
  • duo_sso_verification=p1iT8zKhJnQWRckpBhE7B3X8HFjo5BcKVxLPNOPSEzY4vKJKGtFjGH9VTC1aQkf2
Cloud / SaaS Services Detected
Adobe Microsoft 365 Salesforce Cisco Cisco Duo Mimecast DocuSign ServiceNow

Leak Screenshot:

Leak Screenshot