Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ALSHAYA.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: KW

Description:

[AI generated] Alshaya.com is the digital domain of the multinational retail franchise operator M.H. Alshaya Co. The company, based in Kuwait, operates over 4,000 stores in sectors like fashion & footwear, food, health & beauty, pharmacy, and more across Middle East, North Africa, Russia, Turkey, and Europe. Alshaya manages more than 90 consumer brands like Starbucks, H&M, Mothercare, Debenhams, and Victoria's Secret.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 343

Compromised Users: 1000

Third Party Employee Credentials: 240


External Attack Surface: 144


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse tucows.com
  • sysadmin kw.zajil.com
MX Records
  • mxa-00199a01.gslb.pphosted.com.
  • mxb-00199a01.gslb.pphosted.com.
TXT Records
  • v=spf1 mx include:spf.protection.outlook.com include:spf-00199a01.pphosted.com include:_spf1.alshaya.com include:_spf2.alshaya.com include:_spf3.alshaya.com -all
  • h1-domain-verification=67cKaSZNdwPaCvQuaFtXEU6gc6JwBKp3zBc82p1NaBjnZxhb
  • facebook-domain-verification=wjc77l765pp8c8jqj9ecadyngs6p3w
  • 5l3l1jstc2kz17b0p048xgwr8zxv90qh
  • CKO=cli_zn2jyuku2d7etihzilex7hvhny
  • google-site-verification=IorUBYjJdJp5q6onbOuX_0-KlL9hWtrDRTk-B0FkzXg
  • atlassian-domain-verification=sA6faK4FReWIa0m1vK1jtzJ7GRmbRwtnnNAT6229O8ElK1uMP77OTjsW9XRvSM2B
  • CKO=cli_ig4llncsoobe7nvkkntq56idqi
  • cisco-ci-domain-verification=75e76e8ae36ef084a0917a676e071be92372fb86dba25887ce66818d9373d2e7
  • _iykn088paxpjnlm9q4q9rjji572joj9
  • fastly-domain-delegation-bvheviuvnuikq3j13g-20250407
  • google-gws-recovery-domain-verification=44411541
  • asv=d60aea7dff999d3f851e2e836364ee6a
  • apple-domain-verification=itkkTRUoEFXuOcd0"
  • headway-inc-domain-verification-hg2q7k=CBl8bJ0pkMkik6G5ptfjaYhur
  • mailru-verification: e53234e1b15b754f
  • MS=ms22846234
  • hwc0xkr5gr6fzcq635xl6ml040rdw6cl
  • yandex-verification: be95187a55117d73
  • CKO=cli_hymtgdrd5gduvdctiv5tsce64a
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Cisco Proofpoint

Leak Screenshot:

Leak Screenshot