Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Accenture Breach Evidence & Debunking Rob Lee’s Lies

Group: ransomed

Discovered by ransomware.live: 2023-10-15

Estimated attack date: 2023-10-15

Description:

How ironic! Rob Lee, the outed threat actor, working under the guise of a seasoned cyber-security professional, recently tweeted the above, in an attempt to throw shade at the various claims made about him. In one such email exchange, Rob asks Dragos colleague Nanci Uher for her thoughts on using stolen data from the Accenture…


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 16269

Compromised Users: 35029

Third Party Employee Credentials: 3726


External Attack Surface: 200



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • mx0b-001dcc01.pphosted.com.
  • mx0a-001dcc01.pphosted.com.
TXT Records
  • onetrust-domain-verification=5322fc89fae740838eee535685a9fe46
  • v=spf1 include:_spfa.exchange.accenture.com include:_spfb.exchange.accenture.com -all
  • smartsheet-site-validation=owIJ5MLqX9KoiMfKRnEcU_FVn3xQVPlA
  • stripe-verification=bd6f964c54e62df78d79def27c68a2b4af1c0fd24c5cfbd19097c8cb0e3819b4
  • cisco-ci-domain-verification=757b62f6f592352dcec308d68d984e829ffc63970f7a52579405448c1f39b4f2
  • vvcdtvzwt07bq628pl7h6sy8bfkkc5cy
  • smartsheet-site-validation=E3SuPSHBa_ByQtMfP_CZcDAmeVJu30Ng
  • monday-com-verification=3bD2wbN66_PVrOmLpWA5FS75DF9RC47efxRHg1SkrbQ
  • 4NvLLK5t7rBsujs4vl8VDloZ3mn8L7+67LBKEXUNPPQNlt5lMFpCo2+k2mcJL9EjheiMP3kHyZ+n2UtBLnUS3w==
  • notion-domain-verification=gnhjuSDWpptmSxIQQ47C0Dp8nXcUME25kMxltXMAmii
  • _jjd8gqmmftdv39wwwxc9wzc3q5x90rp
  • smartsheet-site-validation=UN0O6saeN0eC4nwqPk4iRmw7tplSKGNf
  • airtable-verification=b97029e4362bf4a7a0dabc42dd71be89
  • nulab-verification-code=8TTNkc4cj170WuQDQXnntAFmVZulfy8muhpysoP7FuaDXfoObfZUYi5GfIFFO5OI
  • docusign=614ac0a7-7549-4436-b0f7-d6465424f092
  • mongodb-site-verification=cFVXO1EtlHjsZ0uCqBPAVB4DodFYh0wU
  • MS=ms19684732
  • 676294466-1012188982
  • Hp48LTxGknu4omlcp1bP0HqFH2VBFOLA88QS7zwDTJQaM2moc6schoR8P30qVYcuO/RK+cUiCTnntk5pSUk+SA==
  • _mquefi8gk4jfr5u1gv6g5v9quduje8l
  • 8fffc7fe-d565-4d8b-b01e-90c1b0203871
  • atlassian-domain-verification=sM/6A7tL8dzMRpm1KrxPZYnCcXhQqiEJdDjgEfzq7Bjze1IkxLLSHLy92oeUBPsL
  • nulab-verification-code=po38DELk2wUybx9tqt8l1itaG14rCIRuK1FPGoEFPURa5fi1gF1rTQIxZefWdAfa
  • clayton-domain-verification=b74f705c0b4e4369823f5e0717bdaba2abeb4b48d5
  • amazonses:8GzbTEmni2PBRv6jLZwAq1rcYGkbVEmlNuHIcahJ1K0=
  • d0041f5snvpgfuoifaps0gbo75
  • _uq7qnqv26vcv5m5mijdkn7bvlfwmgna
  • remarkable-domain-verification=a3fa4bc4-194a-434b-93b0-26ad640d766b
  • 317d4e96c02745d9a69ecde3a1772bd2
  • onetrust-domain-verification=317d4e96c02745d9a69ecde3a1772bd2
  • apple-domain-verification=UKTR9hD2CBdNapMPHWSIzNhZ76cyAi58RzKRNPjbsVc
  • atlassian-domain-verification=7KcyvCxeJOqBY5fwEHdp8/Nmk9RR7Am4Ihf65044gsFaDhwDtT3fmmt3gdGbur3M
  • pardot1011361=d825a72fd69c0e25f7f62670660ae32a2701e0ee9d280ab006296ed11b058941
  • paloaltonetworks-site-verification=cb18840bf30df87d765413356307cf22e2b11b3a5fb5f389d828f108ce556d3d
  • figma-domain-verification=f7c08cd51dc05c2d7c362e60c65b5eb0df260db19719137f8f337c5c6a47c05c-1734592139
  • teamviewer-sso-verification=fd6c45a9200d4d40a4cf7083cc79dfe3
  • asv=c7a401fd2ce4afdc4c9898caee92a999
  • atlassian-domain-verification=VswdY2C5RSZNJEVpIOZlWC5vgwwfmGckBtTqE6yCtlpOwvE+ryvFXv+1s4LPKBoC
  • _9mrc5vrzqzimj2rx2y1n2f8lr9w4pme
  • adobe-idp-site-verification=228a2025-9a29-4a24-9dfd-4f0b7d1a9416
  • _agr9h4fbo2zwtczr89kzpv57gbaexxs
  • nulab-verification-code=k4l5aMXngpLUhKTLEuiHj2dDFSUBLxoKetjixslAkfHvvwcBagg14LmP9Ru4xUZO
  • unity-sso-verification=be147dd4-7167-4fa4-9cf6-96d0cd7e9e20
  • pardot1011361=55d052b12751cad0eb2cc7eb9cbee111aed934ab445c2bcdd323bcf7591b8053
  • facebook-domain-verification=9ydnlipioha0hvzv7f2wk44xgpu829
  • Dynatrace-site-verification=cf509ddc-d5d6-43a1-a4c2-c120d3b0933b__v9qm0u1chpsc5jhkdpafn869s3
  • atlassian-domain-verification=sQQk6YxOzvD/debvDHjnRazCDNLZ3S0a0a50paa8T6CyuAb7ItKJmb47bFXKHv4f
  • bettercomp-verify=d4c92ff7f01512a34088ec632a21c697438ccc389e17e4c0ad4dfb386a74dc89
  • sending_domain1011361=d2c9d723c0cf979a75118da8b54e4c50a364825840c0e68d68b55e054be61935
  • figma-domain-verification=3e347c955c08b17b30e28103a9f755ce4f119f8936bea56b56d05cf609f88a4a-1745856596
  • docusign=870c49f4-6731-4257-a7c8-4772d6d4dc41
  • _lbtq4qmm1hdxknd8ppwk2qgvxw6pdsc
  • twilio-domain-verification=5f1565b62c940a9ad638e3c7c088dc37
  • google-site-verification=ExtHh0dxqS8yolvzCzLiv6B96zJ-K6a2G1aZ1KUSg_U
  • docusign=e1dd24c3-bc77-412d-ac0a-46a644d9a2db
  • atlassian-domain-verification=59aeShSTbEvs7cB33k4Wsvath8fOirTAy79UnAbOloto0AyhJb41hHFK8SGb8zxF
  • _eao6zm7tpfoi52whz37nokl8z8kze1u
  • globalsign-domain-verification=002EF26EDC67C8BF6CDBC8076E5B62EF
  • mixpanel-domain-verify=9603fa0a-c970-4b25-b616-021ec454bfa4
  • stripe-verification=558d0c1464f98248c5bc40f311e16e3119ebf71f40d426e5fed427acb0a8ddbf
  • docker-verification=dddd690d-45c7-4cdc-b2b8-552178bab04e
  • atlassian-domain-verification=DIJvpa34BYkIAvV7ZxCb6IOGuU7vvIvop5U6m2j72w9/CqLgzWM9DmG/aJd0C5u7
  • adobe-sign-verification=da99fb7e471e8e812595bd6a8c5e2875
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce Stripe Twilio Teamviewer Cisco OneTrust DocuSign

Leak Screenshot:

Leak Screenshot