Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ELCOMPANIES.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] ELCOMPANIES.COM is the official website for The Estée Lauder Companies Inc., a multinational manufacturer and marketer of prestige skincare, makeup, fragrance, and hair care products. The company owns a diverse portfolio of brands, distributed internationally through both digital commerce and retail channels. It was founded in 1946 by Estée Lauder and her husband Joseph Lauder.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 33

Compromised Users: 221

Third Party Employee Credentials: 32


External Attack Surface: 83


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
  • whoisrequest markmonitor.com
MX Records
  • mxa-001a2001.gslb.pphosted.com.
  • mxb-001a2001.gslb.pphosted.com.
TXT Records
  • onetrust-domain-verification=93f60ec43647490b992b7d573fe24062
  • apple-domain-verification=r5h8SQUEMZysKW8x
  • apple-domain-verification=vF2MYV7TRjczkp86
  • MS=ms41387413
  • Figma-domain-verification=aea0a39b9c353297a93e3880b7e5fa1bbcf4f205231842902dc10f44b4ea7224-1718394463
  • rCdXTFtlzLOBay9IDfNowLmDkNjwfNtlxf+3L+N6fGyOsnp2AGiwSv3kHIAhs71EIF2Gb/XiEFSn49BmmBV8OQ==
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
  • 0RqVW/uoONopNV5ovRNNXMiIZ12yconLo78vsgPLPRYhFmxsj6mkkCY+8jL23hlfIKElZmeLrmzIsZKOSfx9Zw==
  • google-site-verification=b8t6WbkYLt4Qf6bvcF280nNdDyUmLxk72oLA9MZVF34
  • ms41387413
  • adobe-idp-site-verification=02ff67304524a5f8333fdfb4ec18f4eaec598ee123b4bd542e44d26a2a00a705
  • 433529198-184237771
  • wrike-verification=MjU2MDQ2MTpjNDRhZGZhN2ZhMmFjMzMwN2UzNWU3OTg5ZWVkZmY5ZTZjNjQ3MzI1NWY3YmU2MTZlNDM4ZmIwMmE4MTc2Yzky
  • successfactors-site-verification=MGE0ZGEzODc5ODFkMjUwZTQ3N2FmODcxNjM1MDU0MTFiODJmYWY5ZTRmZjU1MmUyZDQyMmIwNWFlYzc3YzBlNA==
  • docusign=534cb38b-256a-4701-ade3-f4a33f34810a
  • docusign=10fbf9d8-a497-4613-ad5c-2475ed10747e
Cloud / SaaS Services Detected
Adobe Apple Microsoft 365 OneTrust DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot