Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Finance of America Companies Inc.

www.financeofamerica.com

Group: Worldleaks

Discovered by ransomware.live: 2026-03-20

Estimated attack date: 2026-03-20

Country: US

Description:

[AI generated] Finance of America Companies Inc. is an end-to-end lending and services platform operating in the United States. The company offers a wide range of financial products across various brands, focusing on fixed income asset management, commercial real estate, reverse mortgages, and retail lending. It serves clients through online platforms and its extensive national network of offices.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 9

Third Party Employee Credentials: 17


External Attack Surface: 7


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafety@support.aws.com
  • a93f8667-5772-492e-90a4-1cbdf2233eb8@identity-protect.org
MX Records
  • mxb-001e9101.gslb.pphosted.com.
  • mxa-001e9101.gslb.pphosted.com.
TXT Records
  • docusign=57e64764-530e-4653-b32f-c0582dc55b0d
  • v=spf1 include:spf-001e9101.pphosted.com include:spf.protection.outlook.com include:_spf.optimalblue.com include:_spf.salesforce.com include:aspmx.pardot.com include:relay.bswift.com include:spf1.financeofamerica.com include:mail.zendesk.com ~all
  • _oktaverification.financeofamerica.com=fb463771b8024f22ab1ac7f78f6cd5d8
  • yahoo-verification-key=X4c6K9DoCp89QCEzi7kAtFYRD4SuuK1QrPcwEssUa58=
  • sending_domain46632=6fa8ea3bd73be214e8010100c963883d9e0ecf7f7c358d642379611b708f140c
  • jamf-site-verification=VrsuyhhZsww20vm3GZwQnA
  • google-site-verification=dKSJaw4hBTnC7nH4cW3X5OW7ISWBFuxbxjuiDBnmoU8
  • twilio-domain-verification=5157142f626bbbd6a6dc07d85cd9df98
  • mandrill_verify.Sji19G3x1FXKxzM-bnipLA
  • _globalsign-domain-verification=NOsJyg9fM787Ptj0k03QdHily9MwfgOpCCc8lBsaFh
  • onetrust-domain-verification=f89ddf726daf4da286e8298957b473e1
  • apple-domain-verification=vALrQvL4EFH6jA4L
  • wiz-domain-verification=584c34ad07d65d0ff777e547b77dcfee989fa8f92f94cc01774cfa52881c8281
  • 8062ffbb-7bf9-40c2-a0f8-b58783569bfe
  • pardot_45462_*=fedadc45a91d0452b4122742618b41139bdeed42c4977cb3f229e3c98eb6f897
  • globalsign-domain-verification=BAF4507495D75F34193D2D146B58F38C
  • globalsign-domain-verification=0645E5211CC5C1CE3F217A6D7A908DD7
  • cloudhealth=f3b2bfb3-8593-4bac-a057-6fe71e208646
  • atlassian-domain-verification=5bEMbvrGjHeqXDqmVDPMsZYjx8aMoIz8xs8MZVfF1x6SQaaPsNCf/tM865fTniR3
  • SFMC-ys_U19L3v-lBF2TFnk8fHKp6pmkGGxIZV4efZHWA
  • openai-domain-verification=dv-UsvwynEZSQe9ZMxHgXj0GdMH
  • globalsign-domain-verification=060C8285B943C85C35465D331F8CE265
  • fam-web-redirect.azurewebsites.net
Cloud / SaaS Services Detected
Apple Atlassian Mailchimp Salesforce Twilio Zendesk JamF OneTrust DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot