Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Iron Mountain

ironmountain.com

Group Everest
Discovered 2026-02-02 02:37 UTC
Est. attack date 2026-02-02
Country US

Description:

[AI generated] Iron Mountain Incorporated is a global business specializing in storage and information management services. Founded in 1951, based in Boston, Massachusetts, it helps organizations to store, manage, protect, retrieve information and data. Its offerings include records and information management, data backup and recovery, secure shredding, and data centers.

Infostealer activity detected by HudsonRock

Compromised Employees: 73

Compromised Users: 115

Third Party Employee Credentials: 46


External Attack Surface: 96


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • alt2.aspmx.l.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
  • alt4.aspmx.l.google.com. Google Workspace
  • alt3.aspmx.l.google.com. Google Workspace
TXT Records
  • cursor-domain-verification-f62jrw=3fBXRyi5NvueL1teO8t3rE2yM
  • 7204lwggctkbwv0fs29p9rd19zg3gf2c
  • canva-site-verification=hihVPsmBvc1FLlgv80aUcA
  • MS=ms83837585
  • 1DEC75035305C76BCBF78CFAB27E9CF88B6145795F55389BA142B55E8DE48FBB
  • q8x6krr29z15dlgbh28dkl5v5ks3vwq3
  • g5bWvVxst8NfQiZg9hAXKKSEj8AFBaKqEIFs+xwRcC1lraj7ntrSKXkJyK8NliCI4QgomYUthRXdFZyk3SThsg==
  • cisco-ci-domain-verification=6d38b34089aa214133c0ad5adb38893c14963f1425c58eecc9667f1c7214b875
  • ZOOM_verify_RpvSXSeJcpZydHLsL9J0b5
  • rjjqs2csk5d0hs7v3bx5gppqsqjnzy13
  • flexera-domain-verification-xvcfqkvkhppckyqe
  • traction-guest=87d1d738-0fa2-478b-8d51-576b7d829793
  • MS=ms49767449
  • CF9530291F65024996C44914979678CEBD6D7F32A310A99ABBCF78D4CF37C9EC
  • google-site-verification=17Fy1WorNdZF7i21mO4ndv-3Cn_MW21M8oZrbzazT9M
  • traction-guest=182ebf19-e3b7-45b5-b1e0-b65e208b2bf3
  • docusign=235dbe08-143c-484e-9f35-34b193da2b41
  • _ejygz7c4bp0vrrd5th2a6llyo3roatk
  • amazonses:K3HOgaOq38RcCQSX2AibDuFRoeUl6SDbr/Zw5nN5wE0=
  • smartsheet-site-validation=HJmGA4A3RjgoYqzCTUM8uixzU-oJwUXS
  • v=spf1 include:_int1.imrm.com include:_ext5.imrm.com include:_netblocks.google.com include:_netblocks2.google.com include:es._spf.adp.com include:spf_s1.oraclecloud.com include:mail.zendesk.com include:_spf.qualtrics.com " "ip4:54.240.124.234/31 ip4:205.211.178.0/24 ip4:64.106.173.0/25 ip4:207.166.92.11 ip4:207.166.95.11 ip4:185.92.37.57 ip4:147.154.59.192/26 ip4:12.47.172.0/26 exists:%{i}._spf.mta.salesforce.com a:mail.bswift.com ~all
  • sitecore-domain-verification=bdf8792c541842a89e51a8dff736da64
  • MS=ms20109904
  • 818890cf-845d-4f3e-a49c-33cd38c2778b
  • miro-verification=6493e15f46f9ee4a71ac46391882f9d688167c5c
  • 78qknds98jglj8sbzdxh58rdbnclvs23
  • google-site-verification=RnuA6lzvnkejE6e6KJEUSy-XVDMCPBoBPPV8Q-AIkCA
  • _86p7dmfqdojszsgbn60ylsalb24lbq3
  • factorial-domain-verification=6oKaXdfugYsedjzyYaSEYcTMv169p8Cv28pDVMaYZ8e6e9SfLhpEiDnqVa5VuCRq
  • MS=ms35828056
  • google-site-verification=DOgYElQaATmTObaLoki7S8Ps3FdIAR9PQ4lgs2Xv-2U
  • docusign=5456684a-eae1-4ba7-b137-fdef25572f5f
  • atlassian-domain-verification=aD2FWrQBUacqntuxmiHZW13WRmknjWch1FHgl57RHVvaRpPpJ1ZedxaahvMHRgIc
  • 21c98b4e-75fc-4c83-b391-7f38eef2fe63
  • google-site-verification=_WYWPngBhY-ejFz3iu9Pu-WIauCqp5GofD9OqCJu3gI
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Microsoft 365 Miro Flexera Zendesk Cisco DocuSign Zoom

Leak Screenshot:

Leak Screenshot