Discovered
2026-04-14
Est. attack date
2026-04-14
Country
Description:
cleor.com zoominfo.com/c/cleor/355616744 CLEOR is a historic French jewelry brand with over 20 years of experience, offering jewelry, watches, and accessories for men, women, and children online and in stores across France. They control the full production chain — from raw material sourcing to creative design and assembly — with a focus on quality precious materials (18K gold, diamonds, pearls, gemstones) at fair prices
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 609
Third Party Employee Credentials: 2
External Attack Surface:
49
DNS Records:
The following DNS records were found for the victim's domain.
- info@domain-contact.org
- abuse@barbero.co.uk
- cleor-com.mail.protection.outlook.com.
- MS=ms61549372
- globalsign-domain-verification=IfnRrX5R6B1xUHfDatuh7TXNHDLqWKJ_fHd_yVAANS
- google-site-verification=A-HFSb4G4jG91x5yuIZgTtsNP6814yLvt69EgbAb03U
- spf2.0/pra include:spf.protection.outlook.com include:mailcontrol.com include:mail.zendesk.com include:smtp.zendesk.com ip4:79.99.33.16 ip4:79.174.195.81 ip4:79.174.195.91 ip4:37.58.160.109 ip4:185.29.40.48 ip4:185.29.40.49 ip4:37.58.160.108 ip4:85.115.52" ".90 ip4:85.115.60.190 ip4:37.157.9.156 ip4:95.131.139.212 ip4:146.185.45.228 -all
- v=spf1 include:spf.protection.outlook.com include:mailcontrol.com include:spf.mandrillapp.com include:mail.zendesk.com include:smtp.zendesk.com include:spf.mailjet.com ip4:79.99.33.16 ip4:79.174.195.73 ip4:79.174.195.81 ip4:79.174.195.91 ip4:37.58.160.109" " ip4:185.29.40.48 ip4:185.29.40.49 ip4:37.58.160.108 ip4:85.115.52.190 ip4:85.115.60.190 ip4:37.157.9.156 ip4:37.58.138.82 ip4:95.131.139.212 ip4:146.185.45.228 ip4:146.185.45.172 ip4:85.112.193.63 ip4:2.32.162.128/26 -all
- 8HMEH4TF3L1ER715446OHQU15QZVHJF9TFAYNJKT
- GEngFbqRr1xpiOC63BI8kEJFPVfPG2fqdRmoeojowC2jbRVmD73FN2ZcLpAwWNrPvCNMZUGmsjD3JRyOsnxyiQ==
Cloud / SaaS Services Detected
Microsoft 365
Zendesk
Mandrill
Mailjet
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.