Group:
Snatch
Discovered by ransomware.live: 2023-09-03
Estimated attack date:
2023-09-04
Description:
We are produly present over 10TB ofcommercial data (customer data, finance) for Knight Barry Title Insurance company represeting 10y data. It has over 500 employees in 5 states and executes over 120K service orders annualy which makes over 1M of unique customer data available. Ready
DNS Records:
The following DNS records were found for the victim's domain.
- alt1.aspmx.l.google.com.
- alt2.aspmx.l.google.com.
- alt3.aspmx.l.google.com.
- aspmx.l.google.com.
- v=spf1 include:_spf.google.com include:_spf.smtp.com include:transmail.net include:knightbarry-com.spf.smtp25.com include:spf.rpost.net include:amazonses.com ~all
- google-site-verification=qwVUxzTGEXNPfCak4L2Yft_L7AYFPCsoU2svKLpzv28
- MS=0213639ED9D43E56BB4A62E9355BAF96F91B75C4
- bw=1Cs55V+fD9miPuVpgzycpmQs7sfXxGzmiO7pepLd0KPY
- as=1343921619
- google-site-verification=haYThEVvaSPyjle5Tp-PzhNCaLrr97Rh16_tJwom3i0
- aKlmPbNNmnqb+Jtx0KwEaQ==
- apple-domain-verification=3pUuLUPf6NlvspFm
- cisco-ci-domain-verification=5ef4529892c86db084c75f84baa31f1319a680e2686043964b0cc90048a0c7e9
- c8ns79utrmlpec8o7rjjgjtsta
- oo7l2r6lp116gpkgp2givs8u10
- google-site-verification=zJx2GucQhLKk9tUMpMe4p7Dj0JMBLf40J15fIHiRgRQ
Cloud / SaaS Services Detected
Apple
Amazon SES/WorkMail
Cisco
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.