Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Optima Tax Relief

Group: Chaos

Discovered by ransomware.live: 2025-06-06

Estimated attack date: 2025-06-06

Country: US

Data exfiltrated: 69 GB

Description:

Operating in the state of California, Optima Tax Relief LLC provides consulting services. The company also offers tax liability investigation and resolution, tax preparation and compliance, settlement and negotiation services.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 05824900dc4f73f9e971ff1f07b0ddef-3574544@contact.gandi.net
  • abuse@support.gandi.net
MX Records
  • d148949b.ess.barracudanetworks.com.
  • d148949a.ess.barracudanetworks.com.
TXT Records
  • google-site-verification=Ov3S9zKume8c7uZhC1IoVcc1CrJk8uLi6Op-dnP4naU
  • google-site-verification=ATaCBL3SeC088mhK_gHp1WUQ5Xvho5ePXb14AjoGPW0
  • activeprospect-domain-verification=nOTJPU5dnLLi8WyCafQKuA==
  • v=spf1 include:amazonses.com include:spf.mandrillapp.com include:sparkpostmail.com include:spf.protection.outlook.com include:spf.ess.barracudanetworks.com ip4:35.155.144.170 ~all
  • atlassian-domain-verification=BkiuFnkXyV+EfzdUV6JEMuO5NFQAprq444sIqDzqC6JuHTUdEjUzQPar4Q4x+JbV
  • eaf7fe09d7d983666942346f0a620eb2
  • MS=ms71101182
  • google-site-verification=Zdit9ynBzKvZ_gJySVd5J0z7k1_-N9b8dR7J9E5phqE
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Microsoft 365 Mandrill

Leak Screenshot:

Leak Screenshot