Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Johnson Investment Counsel

johnsoninv.com

Group Storm
Discovered 2026-09-18 07:51 UTC
Est. attack date 2026-09-18
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Johnson Investment Counsel is an independent, employee-owned wealth management firm founded in 1965 and headquartered in Cincinnati, Ohio. The company provides comprehensive financial services to individuals, families, businesses, corporations, retirement plans, foundations, and nonprofit organizations. Its services include investment management, financial planning, retirement and cash-flow planning, estate planning, trust services, charitable planning, and business solutions. Johnson Investment Counsel operates as a fee-only Registered Investment Advisor and emphasizes fiduciary responsibility, long-term relationships, and customized financial strategies. As of June 30, 2026, the firm manages approximately $23 billion in assets and has 159 employees, serving clients across all 50 U.S. states. The company headquarters is located in 7755 Montgomery Road, Suite 180, Cincinnati, OH 45236, United States.51-200 Employees

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 1


External Attack Surface: 1


Exposure Report
by ParanoidLab
622
Passwords
19 critical
0
Cookies
0 critical
Last queried 2026-09-18 08:57 UTC

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • d181192a.ess.barracudanetworks.com. Barracuda
  • d181192b.ess.barracudanetworks.com. Barracuda
TXT Records
  • BPL=2671088
  • f1n46kibbmsd17jbf0j1qp15jm.
  • 5jasfs6lfnffqf9l3l9sfb8b0q
  • apple-domain-verification=2oUKEOssFKT5PeO3
  • duo_sso_verification=3t2ANE6IkkCXf3NdGpKPwnwxAcIpEdv8FDcGDqeC9p0nJP56bPbU53P9QqCjqkcc
  • v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net include:aspmx.pardot.com include:spf.ess.barracudanetworks.com include:_spf.salesforce.com include:spf-us.emailsignatures365.com -all
  • google-site-verification=VxMWjKx8cd8BVEmDovqBQOXItCKpwAJeoMJgD3yn3AM
  • cwRIdbJc43F7xird33jbp6hreEXV4H6fmPhBPkAwn6xBRGE1RwttD8Vl0NdnexuCtGA6/hlkKYlyOTWOhvMkgw==
  • docusign=ddf4f228-fe0e-44e4-9c26-11bd048fbf4b
  • pardot511351=da27a15c7cb6fdd1a850477205aed99c8375fa02e30aaa4de683eec74d601e4c
  • ms-domain-verification=83002727-45de-45b7-8fff-a6829fc27dd8
  • MS=ms55519690
Cloud / SaaS Services Detected
Apple Cisco Duo DocuSign Mailchimp Microsoft 365 Salesforce

Leak Screenshot:

Leak Screenshot