Buy Me a Coffee

This space is available for sponsoring Ransomware.live Contact us to sponsor this space

Logo Albion College

Group: Medusa

Discovered by ransomware.live: 2024-12-23

Estimated attack date: 2024-12-23

Country: US

Description:

Albion College (founded in 1850) offers bachelor’s degrees in business, the humanities, fine arts, natural sciences, and social sciences. It provides study-abroad programs in Europe, Latin America, Israel, Africa, Asia, and Australia. About 1,500 students are currently studying. Albion College corporate office is located Albion, Michigan, United States and has 412 employees.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 260

Third Party Employee Credentials: 28


External Attack Surface: 14



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mxb-00802e01.gslb.pphosted.com.
  • mxa-00802e01.gslb.pphosted.com.
TXT Records
  • google-site-verification=BC8SGUlmLYElbPyPiminL8aI49ZEnOHeOnDiln-3-ug
  • google-site-verification=fxoowauOBBel25D_2lh6vifpBW7axPsmc9mTS-AlDDg
  • google-site-verification=z6kW0KwAopAZjt7wadtZ6W0ohPU5-fycZRhx-6HJL3c
  • v=spf1 a ip4:147.124.0.0/19 ip4:52.86.188.131 ip4:52.43.50.148 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 ip4:208.117.61.155 include:spf-00802e01.pphosted.com include:_spf.google.com include:spf.wbm.ai include:spf.dynect.net include:_tuf-s" "pf.touchnet.com include:slate-mx.albion.edu ~all
  • yahoo-verification-key=EnVR7nLKEXxQ0sRHDRMQcvQm2i1klhmqmWxsGzVmFVM=
  • _dashlane-challenge=e66897c3616235758c9b9295528ca9831a1e181c24ceb576c38a2c05dd893da2
  • adobe-idp-site-verification=0b67cb810ba5e0acaa5d0d0c2c489bb3dcbab73c81cc804351f50f2bc9b88430
  • amazonses:Sy+f9HSiQtp0/ISU4l0VmsmSR6DBHKpQC75oifvMqpg=
  • cisco-ci-domain-verification=2d1d54d78b08ab4bae15b30e9604f770f9d4a4fa1105878db33dbb131313901c
  • facebook-domain-verification=f9uh9bmc8ufg2oavsvta8v235w2mfp
Cloud / SaaS Services Detected
Adobe Amazon SES/WorkMail Cisco Proofpoint

Leak Screenshot:

Leak Screenshot