Discovered
2023-03-11
Est. attack date
2023-03-11
Description:
Founded in 2013, Delaware Life Insurance Company is a subsidiary of Group 1001 Insurance Holdings,LLC (Group 1001) a dynamic network of businesses making insurance more useful, logical, and accessible for everyone. As of June 30, 2022, the company had assets of $41.8 billion and liabilities of $39.7 billion (does not include Delaware Life Insurance Company of New York) with more than 320,000 active annuity and life insurance policies.
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 21
Third Party Employee Credentials: 1
External Attack Surface:
2
DNS Records:
The following DNS records were found for the victim's domain.
- mxa-00918701.gslb.pphosted.com.
- mxb-00918701.gslb.pphosted.com.
- pn8np0w3n3nlp11dghrb3vc821b6jxj2
- apple-domain-verification=p6Fjv986tRlriPsF
- miro-verification=dc614ed63fc87cf643ede418866233245c160492
- adobe-idp-site-verification=95a81f59c61273c37331f5cb46406c0e206c27707159bcea11728668a2da57fc
- ciscocidomainverification=3310d6beaea937da47c6cecee49daaf12de7cd8e30f759af2fc848ba5a8880ef
- 71h7myqg9lzbh18xpz4y5q9rxj2gd4q8
- atlassian-domain-verification=94rSdZyaIJUZt7Os3thLBtufLl9eioruFGGR36dsdG0sj6ErTVI0vpy0qs8ptk/7
- v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
- zywave-domain-verification=Z5OgqofEM5qniQkzeLje/qUnRS+myBF6Kh3TPNfjZ9c=
- wombat-verification=3KwxVCQV1HEp-aRXRTKKaZ5G0frhk
- md1vbxsh35zxljcv4yx6szzxfsc9vrqh
- _ozxxebis5yif72o7py7duxjohho7bje
- _gitlab-pages-verification-code.delawarelife.com TXT gitlab-pages-verification-code=077bfb6a7f761467bc5f58c06da71c03
- 9jzq1ghzzjlk6fp80vpmbkx83hd06lwn
- atlassian-domain-verification=YmhAEI9QHwhySRzhGVdnuqMTGw6Ij7qzqJJLDr8tBGe4ezaDn0Qr3n1gJTXSrjqN
- teamviewer-sso-verification=9933b8dae0b64a758b4117c2f6909c9a
- 20230202190024015095re6p3cdlll46tbe5fxlthrf5yb84k7gfobnuctwiyv15
- slack-domain-verification=YdnMIY2Buqq5HZQnn4e5TgUu1HUDydmdozu3QOFf
- canva-site-verification=z42yeTNNGRPiUw7ROQJJRg
- smartsheet-site-validation=jTijE9eHndKIf_nfZPr5QPOWT1lr8ryX
- n7x7dr3g37td4bdpx20w747cl3f6cjr3
- google-site-verification=n8LT_xGDjNl_B0yR-2E4Xp8BbyKLNUwrNtG9vVx_GTc
- 3168875
- sjr0y2xl8wxlp9j2z1xbw50fkqdw51lk
- google-site-verification=Hq20z1kT20ceRu6LMKrn7_u9iF88WaNAZoq5nZE8tyU
- MS=ms76946822
- atlassian-domain-verification=8mxYBFXqQE+rrGeQfiifDN5u88RcxTL8eqNijtLnmHqpGFv9G5VyZxpTF9K53zNX
- google-site-verification=yEoN_taOP4bMyBwF_BuPn6LlWP3yyB4QrCzqboFPStw
- proxy-ssl.webflow.com
Cloud / SaaS Services Detected
Adobe
Apple
Atlassian
Microsoft 365
Slack
Miro
Teamviewer
Proofpoint
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.