Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo HUMANA.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] Humana Inc. is a leading US-based health insurance company, founded in 1961. Its coverage extends across the country, providing a range of insurance products and health and wellness services. These include medical, dental, and vision insurance, along with pharmacy services and health information technology solutions. Humana largely focuses on senior citizens, especially those enrolled in Medicare. The company is keen on fostering healthy habits and promoting preventive care efforts.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 74

Compromised Users: 6972

Third Party Employee Credentials: 139


External Attack Surface: 121


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
  • whoisrequest markmonitor.com
MX Records
  • mxa-00496301.gslb.pphosted.com.
  • mxb-00496301.gslb.pphosted.com.
TXT Records
  • onetrust-domain-verification=b535d5054aa74c46a51eac792d125d8a
  • onetrust-domain-verification=c8a0d909db9a45d0891c402496703277
  • onx=d8d8b28a-9abe-4289-9316-8af843dcad37
  • duo_sso_verification=ntKNfDdVJei8KDrVP96Ly3bVqgMjv6xy2cY5ZibIKrEliLMVTrphd7lBvSnSVSmv
  • ahrefs-site-verification_1b28cc1703a32b253c6bc921cf7cfc57f57eab4fdb32013cc7b7852aa27a0687
  • PzHUpXxDORNVWoO6/0JO9j7ZU4FxtRzy+74F3aua8/BazdJVg3ujXk4CmIsbczUSZ8g/XhTLgYPcziUt8YahlQ==
  • onx=e8e99e4b-c12b-45e4-a45d-97b01353d907
  • adobe-idp-site-verification=3cb86be2-909c-4b1a-8b16-42949b5b1b39
  • onetrust-domain-verification=61d025aa26b9481881e0710be1843a26
  • google-site-verification=jqdS6-Y2qapPu5zmpAarOI5LZ7IqRSBAkPTindwsMLE
  • vmware-cloud-verification-7b989b88-79fb-4fa4-a09f-9b3946490753
  • k2zjm90vd8qr1p338bk4zxnyjx9wzdq7
  • ciscocidomainverification=4d4f35fd0656bc1d0f8bd4baeee7ed109d2b9675343cf13ca2fe716c2c6f97d9
  • postman-domain-verification=c08cbbcf7f6d5c4897da74ef84c640c19edc9ec4ec6886e13d03edc7645d243d4d630a614f776b4d2a4a85bd1dd30bd64b982d96d88b203aff4d775f13c215d1
  • google-site-verification=axLPNsiCiBzkDLxvIp59E1Fm85DVtkC0BZee0shwSXM
  • apple-domain-verification=dqq9zPCRuOiKKNIQ
  • jamf-site-verification=t0EKIKs0ICX2AAwQf1KINw
  • google-site-verification=zSxrBb9WqUkJhb2y4r8J5G7jp2seRWasJenS74znlFU
  • onx=5d425e8d-0469-4e56-9341-7274d4065f8a
  • adobe-sign-verification=22ccf7c28cbd046e0cc08985a3f0bd0
  • google-site-verification=0m9v1aDXY_2fPxZ4aM686id8BJUZuICt8hFEK8Mlm7Y
  • amazonses:JSzakwmnT/jCUFM7rJ9bllYyI40w9L4fmsNqEm80Jug=
  • mongodb-site-verification=hQw02Mp6s2D8dSztUuYFL9VFrBo219OB
  • xuJjzmsOnIdVBSgj2Q6L4pLY-Uo
  • onetrust-domain-verification=3284ec94a1154bc3848e61cbd096cd2f
  • intersight=f0f5fea21cd68ba40c567f81349ce917ba8b6db62d2c4eb8d1dea71698aec6b7
  • docker-verification=f3880919-eb20-483d-b051-ef1347da5439
  • MS=ms88681392
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
  • facebook-domain-verification=inq9f2tzwqcl99hjorqifvpy8d55fz
  • onx=5742cf93-fe75-4362-90f1-c6668dd5c0df
  • amazonses:ebMGW7pKb5Fi553zmj4GKaYqbXWTGpUAoQbu69zrNZc=
  • dropbox-domain-verification=6d1q156pkzkh
Cloud / SaaS Services Detected
Adobe Apple Amazon SES/WorkMail Dropbox Microsoft 365 Box JamF OneTrust Cisco Duo Proofpoint

Leak Screenshot:

Leak Screenshot