Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo MACYS.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] Macy's.com is the online platform of Macy’s, Inc., one of the premier retailers in the United States. The company offers a range of products such as clothing, accessories, home goods and more from popular brands. It also provides features like online shopping, delivery, returns and customer service. Macy's.com reintroduces the convenience and ease of shopping to the customer's fingertips.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 46

Compromised Users: 30003

Third Party Employee Credentials: 52


External Attack Surface: 105


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
  • macysdns macys.com
MX Records
  • mxb-0009cc01.gslb.pphosted.com.
  • mxa-0009cc01.gslb.pphosted.com.
TXT Records
  • google-site-verification=TYUtXtVkDiCMSc3enxnqX59CLTiDiyNbf1ju8704UA4
  • adobe-idp-site-verification=4e9c2f2bb4cf3e66ef521a195b9b488e69d330fed4b5fe80ac814669d7d9a5f0
  • box-domain-verification=98611f08b4ce3abd122895e6883fd760315d1feb5ea684d9f1f1c4da432018c0
  • mongodb-site-verification=NBCPowJ9SyFXv4N4PhpsHSuOEwqSrLXE
  • heroku-domain-verification=kdnrhzqtkm4r0ragrwkowsrffoka5sy0xj18q829cu
  • intersight=c16f14811be1608418c466dcd90c820f49606ddf06802d9924013c9cdf1dae94
  • extensis-domain-verification=b6a9468c-7909-4925-8f04-d1107de68cfa
  • onetrust-domain-verification=1eaecbc366724844b5a4c518a537ff16
  • google-site-verification=MdnAKx0GkplXggnt9YLd1TQM749yPjTYzl1h7qunc-A
  • MS=ms42514781
  • google-site-verification=5db5db4h370L_xTGkZFWTt4DS37jD9MoMNfgbSv3Ht4
  • google-site-verification=k6xLD0gGGFRcQ3I4CmtsnolfXf9nWVoX15vpV35yCDc
  • heroku-domain-verification=glbilejlzmvkvey7rlfla324kk/axtyvxjqy/roi
  • google-site-verification=KvU5y4HxLBHy0Wzr5TlpJzRTjToIThYQJx42gIOY6IM
  • apple-domain-verification=icRQk9How8pN8hDg
  • atlassian-domain-verification=SUqM5OsJ3RepnWYwYrJ1QmUY1yFxGUBk26RtbPxvp93m4aH2M85VaX9VwUl9asgm
  • facebook-domain-verification=s7fgjz2obl9y1hphphdm036q3ga6v6
  • autodesk-domain-verification=H1bZGea-auZWjRKqPWeP
  • Value = cisco-ci-domain-verification=1da236168126214530fd9bbd8b4f20dede17dbc4e85d7bba104b7e232289ebbb
  • canva-site-verification=B-fhSpcI_i1L4iR4NTMx0g
  • Dynatrace-site-verification=5d4bd67e-319d-44a4-9cd8-313950577e34__e1k39uja672gp7k508hov7jlc3
  • google-site-verification=59bL16t-JCtZIb-Getjc3eHeDJpeyCyZY-J2c106TZQ
  • v=spf1 mx ip4:208.15.91.0/24 ip4:208.15.90.0/24 ip4:204.214.48.37 ip4:69.25.227.128/25 ip4:74.217.49.0/25 include:spf-0009cc01.pphosted.com include:mg-spf.greenhouse.io include:spf-a.rnmk.com include:spf.protection.outlook.com include:mailgun.org ~all
  • 3R3unSHIaTa+sMJdJbguCAV82k24b51KSOBavkwB4XWsoHskXgEJepsQogYJJEJIQ7/aRZ0Sfylct+06Hn5Ifw==
Cloud / SaaS Services Detected
Adobe Apple Atlassian Microsoft 365 Box Autodesk Mailgun Cisco OneTrust Proofpoint

Leak Screenshot:

Leak Screenshot