Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Redact
Discovered 2026-06-28 08:38 UTC
Est. attack date 2026-06-28
Country US

Description:

Sector: Medical Supplies | Revenue: $4B USD

Infostealer activity detected by HudsonRock

Compromised Employees: 8

Compromised Users: 64

Third Party Employee Credentials: 18


External Attack Surface: 44


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • mxa-001dc502.gslb.pphosted.com. Proofpoint
  • mxb-001dc502.gslb.pphosted.com. Proofpoint
TXT Records
  • miro-verification=f68cfce770de8954ac99f169aed695507f3ffc02
  • docker-verification=6234e633-f0c0-4997-b99f-0f21c10b4f54
  • google-gws-recovery-domain-verification=59545787
  • pardot1017533=3e65a06574c10a502dc71f6ac8a3d77df1775fd855f7382e66c855e1a4ff02c3
  • pardot127431=149fcfedfc824dafc79f9542c9dae063278bd6f4dbf43ee0d8c6d1ba4db79e90
  • docusign=3981dc78-892c-432c-8c72-916d66b5f312
  • Fd/8mIReEYNdRrdwwdVVTP4fXqmA6VxzaQb8S8KZF07yjIDOZ089YgJavcxwdSvO/lwoaVuDMs++iKaVZhhe7w==
  • pardot_127431=9b7ccbaf672c0e689a7775bc0f2bd31fe093f9b22a6361fd613a9e5d55007ac3
  • sending_domain914031=97dd23155bf07c681843b22f907005fefd853bbeea039ed038bca8db33882f16
  • neat-pulse-domain-verification-nMVpzmv=13abba69-0128-45ca-8244-7ca066fe95d8
  • intersight=8f77924249b20533e1418ad982c3b5f00e2d1633b8be9f540d892c8c1a4a1199
  • facebook-domain-verification=8sr154w66r2h3fohxfig0a6kwcam31
  • adobe-idp-site-verification=40412b54dcf2a617c817f848f5d920a39967f8fd2fbe623387bbb52324549978
  • asv_domain=24cd2451105948e7714edad4e580
  • nvh26lv6oqjhq0kv68g3tvgf3t
  • atlassian-domain-verification=ELVQiUhIFHSzkiUO9Wu3V4RRajrdZQ2JFK5zxppJuynTyWHr3lnQoAczHA2/UmYa
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:rp.oracleemaildelivery.com include:_spf.qemailserver.com include:et._spf.pardot.com ~all
  • docusign=55a8ff97-cd09-49c2-870a-c71de5456ef8
  • docusign=b42a49a7-12f9-4650-94cb-92e0251ab360
  • MS=ms91259225
  • google-site-verification=MEH1stG3WuVq2yeFMDjpNVOGR1K2aPInNNP2wbbj-8E
  • paloaltonetworks-site-verification=27375d9a131619a995bf82c919e5bb0145d1967c350a42051c9d5e89df398bad
  • docusign=199491de-a4fc-4cb3-a395-00f7e42970b9
  • sending_domain928883=13110f8e1f229a56dde4ec6698b2f68b5810e123a91186f405e9e899f5ed9c82
  • atlassian-domain-verification=SHBrdokJ75gPm1UiS9qfkEc8o//npBQ5YPZaAKpROZfSwNlRaUV8MkVXU0xEf11L
  • google-site-verification=oxP6bEBDlanMfor-pffJEG32Tt9vfbP9lXMG9RTcMK8
  • atlassian-domain-verification=oF9hvDhgl1JNQZScHMl0zkgsrRgdr/ynaTxHGO1TKObzy8W4wZS1QUCO5bDw9icJ
  • google-site-verification=akmvwk-pbV81GQYifbElO_NVfiSO8iA6wLUNpAU8m8I
  • ciscocidomainverification=60f02978917010de032a23728813e0a85d50a709854e133ed491c6689ffe57ab
  • 6vfJSDDmlCZXquECGiIVig2KxV51ZtwN3G8W6jeLTsoK7/7diDW8y30KtY5YAjQFKq35FInyV3bBWJNI+2rYIQ==
  • google-site-verification=Z5yM8mXiyR8y6q3lb19hXoIUgn-ndQcJJO2hCUf_stI
  • smartsheet-site-validation=CXRlQxeauH1z7UAiXD4nC5Rtskb46Wg2
  • vmware-cloud-verification-b7e61358-75a9-497d-ae03-6c212362073b
  • anthropic-domain-verification-7x9nwv=LFoZREvjHKJTne72I5NzVTFD4
  • docusign=2107b3af-55ba-4922-b12e-9afeb202147e
  • apple-domain-verification=0FBDcXfKDMISJqVk
Cloud / SaaS Services Detected
Adobe Apple Atlassian Docker Microsoft 365 Salesforce Anthropic Miro DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot