Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo HARVARD.EDU

Group: Clop

Discovered by ransomware.live: 2025-10-27

Estimated attack date: 2025-10-27

Country: US

Description:

[AI generated] Harvard.edu is the official website of Harvard University, a private Ivy League research university located in Cambridge, Massachusetts. The platform provides extensive resources about their programs, academic departments, research, libraries, museums, and campus life. It offers information on admissions, financial aid, courses, faculty, and alumni. As a globally recognized educational institution, its online presence serves students, educators, and researchers worldwide.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 335

Compromised Users: 18240

Third Party Employee Credentials: 241


External Attack Surface: 200


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mx0a-00171101.pphosted.com.
  • mx0b-00171101.pphosted.com.
TXT Records
  • v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all
  • atlassian-domain-verification=ASRKBXyOafZgDCRWh1Ylv34hiOSMgAIoNXs8H57rR3aTkuOD5KwJfUN9G3f7Ah/H
  • MS=ms35192554
  • pardot_378242_*=8b485d5cd9114869cff8f307da5fa9287434ebec11621d88c07ce97a7fee06e0
  • status-page-domain-verification=p83gt91wpxms
  • airtable-verification=b25f432db3cbc5bfc481914364b6ce41
  • globalsign-domain-verification=1DDF777ED1ADF45E5FFAFFAAD6774180
  • globalsign-domain-verification=9ff12eafbeebb02a0f2b0383aef9d1fa
  • google-site-verification=DzhZyP8pu0M1-RFghfTcSN-9poidboYRNdfn2Rf2hCQ
  • heroku-domain-verification=1qfmzz9vp3kexf4fr5zuliwvpieih2ffz4gexo7tlh4
  • globalsign-domain-verification=C44DEEAC45AB4DC2B5AD0B9B2E5D5803
  • google-site-verification=xqg8LPF_v_QMEIST789q8xhRDqUEX4_8lQjAvV6YykY
  • Peh2GHoW8uiAzwS9tTZKlGBn9cMq6Y+XUFtrqmLtqFh1WvloPkzGczPsZcSdDfin4hZ7QiL9J7SM8yr7Yyzi8w==
  • xIGeuA0e5B1BOjTE4IBO806ziFX9G1m2dVJ8zO7CMkmKwZ6MEkMXC0P7n5SRCGOdS9jbceH/7gKYgD4h9FBGKA==
  • geneious.com:domain-verification=1781B6exIEsRBzJ0KzPtKg
  • globalsign-domain-verification=B8359DCEFBCF837B95E2F82282E4297A
  • atlassian-domain-verification=Z8oUd5brL6/RGUMCkxs4U0P/RyhpiNJEIVx9HXJLr3uqEQ1eDmTnj1eq1ObCgY1i
  • openai-domain-verification=dv-e8vYSnmmPbWxpNte1iIKgvOO
  • google-site-verification=NEWpTHNZnWRWN3trkIMeFbuPVG3ExwOXUHlC9aJ2sks
  • google-site-verification=pWvLuNePLYxAbafZw2a95vnBhvcj12DzM9NulT9ujSY
  • pardot378242=7001579db574e062735763ba81b54da111abc31facf16bbfa653ab6b8a770988
  • anthropic-domain-verification-gy5zhc=zmrGT2kyyc2HlnUn6f0utkQB6
  • brevo-code:30d9f789747b4c124f72dabf24a0a97f
  • jamf-site-verification=_Bno41ta_Ef2G0krod2Oow
  • _51a79b140kb1cu9o67nzuefyhhxthv9
  • openai-domain-verification=dv-5z82SztO32q9YBNgFooNBz5v
  • pardot962443=9098884472c5cb29a2e20700b41411cb4aa5ebcf340360e71b2cd8464d8864b6
  • airtable-verification=a92cef30671587a4f6deb7951c1c3f1a
  • jAykGnWytyLeBseMa8x2/MBve6/yQqana4yrAc1ROoei7uZHUkM2FU0Xx4qI/rm+kOGdImZdoq0fdodgLEw1dg==
  • google-site-verification=xXWxVElKH8ek_eW45CbAqVSMTQgAqLYUNQUrWpOmkrY
  • globalsign-domain-verification=87677a19ae97bfbeec25ff1510a80420
  • google-site-verification=MmfJS0BjLRgcxrlj8kAyNdToKeAmj0fKb-lPOnd5Pmo
  • adobe-idp-site-verification=66e813947c764d98330002232f383a68df8ad609065abb9482f3805dd2a1902c
  • google-site-verification=DZTZhbBaYJ6AO5j-tHFYBdkwryNywFh2gMUeg3SRDSg
  • atlassian-domain-verification=OYfkFwspEELRW6A32BsDVWgvdz8/pLBxVcq7s/mHLBVGqRQRG58XA5LRtDAGpfA7
  • pardot679353=3cc5e124c5020a1e160f01981f45be33a467a1c802711e0e5654184ef56d18c9
  • globalsign-domain-verification=dcc2e5d0d67efc32044ae679c7cf19e6
  • globalsign-domain-verification=1C94E0FFAAE95796F597427644D90C03
  • pardot679353=f93ea3588d69483bf48dbf587511f51d43ddadaae52b8bac6856c8428559a06d
  • globalsign-domain-verification=5A1F4E0081852ECB9015E837384121AD
  • status-page-domain-verification=b4j4g69th3vv
  • fastly-domain-delgation-vdnblsdg768nm-21052021
  • google-site-verification=lY-T8NneGQX1RGXeaoBJjSmT_lx3dLRKDq1xY44ZI5w
  • airtable-verification=8b8110e9283dd87d57b3c5f2f5af2db1
  • ciscocidomainverification=41ce9827e3fbbca9ce75d5dbb5a6bc7b089dc4e239c1b56ba828216d1214480
  • smartsheet-site-validation=jfLh_IkQNJXuKKpTn7RydwiiaAOLy4CR
Cloud / SaaS Services Detected
Adobe Atlassian Microsoft 365 Salesforce JamF Proofpoint

Leak Screenshot:

Leak Screenshot