Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

ActionAid / TACOSA

actionaid.org

Discovered 2026-05-05 20:31 UTC
Est. attack date 2026-05-05
Country GB

Description:

NGO sector. Domains: actionaid.org, tacosa.org.za, immigration.go.tz.

Infostealer activity detected by HudsonRock

Compromised Employees: 11

Compromised Users: 48

Third Party Employee Credentials: 129


External Attack Surface: 27


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuseenom.com
MX Records
  • eu-smtp-inbound-1.mimecast.com. Mimecast
  • eu-smtp-inbound-2.mimecast.com. Mimecast
TXT Records
  • apple-domain-verification=U4xwIp25Mrmf7oMw
  • google-gws-recovery-domain-verification=70179934
  • 1002o4q9feaqgob1b3vq6r7dpe
  • atlassian-domain-verification=6MKtM9yKP7FayXXdjTM37bFJEjnJ5u/bZ8h2ji2q22nYj2JCgqZQPUAyP0DQFn2y
  • adobe-idp-site-verification=6a668b7f61546d9ec4b19fcca3d0fb9389e568f8889684c0ba758968ccdf9a29
  • miro-verification=ba3ff0bf612763e603ed2d43ab4b9609db3c58b7
  • v=spf1 ip4:195.130.217.0/24 ip4:91.220.42.0/24 ip4:146.101.78.0/24 ip4:207.82.80.0/24 ip4:213.167.81.0/25 ip4:193.7.207.0/25 ip4:213.167.75.0/25 ip4:185.58.85.0/24 ip4:185.58.86.0/24 ip4:193.7.206.0/25 ip4:147.28.36.0/24 include:_spfprod.ngpvan.com includ" "e:_spf1.actionaid.org ~all
  • N8QAFQGJGXSS2MIX2Y29KTJUMBDVB6MZIIP454CO
  • vn4eo3c0827m6k8aihc54tffu3
  • mailru-verification: 5f09e509bd10122a
  • google-site-verification=MjzzD_7fKVQZNtl_lV0uHNOU4bYWTb8wI7jmROT6J5M
  • DiLMKRHJZA775/m6z7rwdrbiX8vXd3ycYbmCvr6zn139krOD/SpanPQZFLtdrODo81GY4b75uDZktX8oD2vFig==
  • MS=ms76735538
  • google-site-verification=yY0Sc6yjQERb1cFVNtvB9Qh2h6u5m5bnyPjipAFlKvo
  • google-site-verification=DyFt22IlSUDusUPuHrVBQPffed_GRiKLMu1-7I1SF7I
  • brevo-code:1677de4d425e122acc3e97d0e483da85
  • google-site-verification=X2eSceVfyYAokn34VP3UENIK_rZs5rmsWWRsOguCNew
  • d5ulu0ehlpvafi99aa7uqkp2l8
Cloud / SaaS Services Detected
Adobe Apple Atlassian Microsoft 365 Miro Mimecast

Leak Screenshot:

Leak Screenshot