Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Ingersoll Rand

ingersollrand.com

Group Everest
Discovered 2026-08-08 12:24 UTC
Est. attack date 2026-07-22
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

[AI generated] Ingersoll Rand is an American industrial manufacturing company headquartered in Davidson, North Carolina. It designs and produces a wide range of industrial equipment including air compressors, power tools, fluid management systems, and HVAC solutions. The company serves diverse sectors such as manufacturing, construction, and energy. Formerly part of a larger conglomerate, it operates globally across multiple countries and markets.

Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 208

Third Party Employee Credentials: 8


External Attack Surface: 66


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaintsmarkmonitor.com
  • whoisrequestmarkmonitor.com
MX Records
  • ingersollrand-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • se6ukg0a5ce6qbn6cm0id93drq
  • 4pggsvp2ddx1wsx2k8d8m0fl7cgzxqh3
  • _0adkoafmpx0pj6zt1to1xzwe2o54q9e
  • _u5o2v70c0lfnn1bhndj5k0zz71a2kcb
  • 94fxgdzvs4swmwzsnldtxw8rmqdq9w2d
  • _ol06kwj7k5ubydst6snys3wnya7lfsk
  • l4y5nfq0fsh21r1tk2xhkcz4dfgh2x7n
  • 692vbwf6cl2vh2ppsvcnrwp3fbfn56hx
  • _v3z1yr5vpimyjc7vfve730sfmtq9kl8
  • _uhea8x8hu8dsugqfczlape6lixjtfkh
  • mgchmy811klxg57qcppbdr79qhh52jh0
  • 9rlq89378fc3y3p1tn3cbhyzbdkt34b4
  • pjl49d5xhgxfjv9ln4kq54cx705xhbmv
  • fwy3f1qwjk5vjx7mzq0f9cwj4wcblk9v
  • 4vbs1bsxr3l1bmc27dtr3z715q6sj68v
  • cwqnf0xzzqv7h9wxdlvdff7bg1k9sfpz
  • _1tuqofmhi1huzync8nu4a9ftvmrh4ul
  • x2rfnqxp12ynqhrqs7fk6fhsdxsjb7h7
  • _lr3r92w49vvnhi6x9bcr0lp9mnhrcv3
  • _3ma639rxr419dt3dudu5kh2xqs8p2l8
  • x4c1xg1638b1ksrngdnzd9l70wx762cr
  • wypn5dyp34t72dstg34f5719t85r36jn
  • k16xlq1wkzy47ywbpk6rgps684dq7fmw
  • google-site-verification=G1yl8VUsDEiB8OxYtrp1rYCnSLPDShiqlzIpBfbqXfg
  • v=spf1 include:spf.protection.outlook.com include:amazonses.com include:mail.zendesk.com -all
  • _wgwjkbcva3ymtldn81u1qkqbcsz9ml1
  • _ur1j7rxwm6sh1p6sfiidtodmxwjbjkc
  • fwq961c3r2tsjg033z8dpdqgfvbpxfym
  • _xghjo0j29ae623y16nr9aiznxdgv1iq
  • bljvz8w1619rmbspbhvjcg8x0n28frbg
  • _wo2vw8z5gz13ngcn1q42bh1d0uhn5c7
  • amazonses:TIqvjAc6Iba+sWjU9yVD2uHjRzHex8XWHdbLuGuV7jc=
  • l1tjv3vb4f1drbsflvh9lp4vqf03mp2z
  • dbqpzx40xl83y0fczr02mm8fcd5wsz3m
  • wydqdj653dl4jd0kx8vb11zdqlchcyx0
  • amazonses:3uNI/EIHMow54jzxzaJtNPT0rQ80TvO0EPRaebi25VY=
  • px7k5867381g167k27sspxhpljfj366k
  • 1wg564wrgx41htdmwsl6mb4rqhs7v56h
  • rvk5bavnoude7uuac93b56ds5s
  • nwg37z36nsnxk7t4vztqv9nz5jpgkm35
  • _ns87pupgo5oe18vxj0m4dbnqd8muldy
  • facebook-domain-verification=skegjq3rwfojlv35zxj4kf771s6ipf
  • _dwt2egbjh4br2qdl0j0tpz0awtc41fd
  • zz4654n5j4k5znv7clcj39hldm4vntzt
  • z2cw7w9d8rr5s18b5sbv4wnjvq3rwv1y
  • l7sd6gwytmb01xqmtf42ryjrydv4xbtr
  • amazonses:6bIACMBdTOK6Y/PmOdzUmnMRdq9G0iapHc1G2EiXE9M=
  • google-site-verification=nQ1HbgPxgCKkoyOJtQHPF4jc9EZ6DJefV_eg29RVvtI
  • MS=ms98069388
  • amazonses:7iC0iFnyLVUFcM4tcesQKcQ7DqdGXG1C8U5DTA3iK8o=
  • 7bxqjmgf91jnptym374hqjt59v12f35g
  • _tju3biewa1ds5bintpuk6vhhxuo06n9
  • vksl8q9sc251p10bzv41gpljd4rxkbjk
  • google-site-verification=mC5e8_7OpxwE_UJ3ozoS-bIIHUKCQKnUhA3E758CHgM
  • google-site-verification=FfP5UYNgqDMOX7BrlhOL9CouCSPpMx5Qp8pR-Fa9cdg
  • amazonses:0UAoQdYCVMyE0gtwGILXL+AzyUJ+agi6K24tzljtCsg=
  • 9v152k21w0j3wpkcnkksyx1wc7y6kyj4
  • nv6ycgc2lj6k6kymjqwpnd9tf97lwtww
  • amazonses:w6AGvPo9JN7rkTa38vTnbFaMGZL+0JfWS32N3tDs4ro=
  • 0817gmjfhlypm37d4xv4tnlfr72ndths
  • 3w80xrx12x5thw3tsgc7xzwlbp74mthd
  • qd1hv7k5nts8r13614d49ajn29
  • 63dcml4mw06vbqml16b1fc69g0fvbg7l
  • _09qsfjgxhiq2u46wqgg1ytd0p4j08yq
  • _wmkk486rpsjih9e0bkoswzsl5c6uv46
  • cc09wj07y09rm0c0fwcm3xggbydcmqff
  • _2ae32zvimruh9rp1brol366d153p9cl
Cloud / SaaS Services Detected
Amazon SES/WorkMail Microsoft 365 Zendesk

Leak Screenshot:

Leak Screenshot