Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

MICHELIN.COM

MICHELIN.COM

Group Clop
Discovered 2025-11-21
Est. attack date 2025-11-21
Country FR
City Clermont-Ferrand

Description:

[AI generated] Michelin.com is the online platform for the Michelin Group, a leading tire company founded in 1889, based in Clermont-Ferrand, France. The company is renowned for his contribution to the tire industry, including the invention of the radial tire. Apart from manufacturing tires for various kinds of vehicles, Michelin also provides travel assistance, publishing maps and guides, and operates in more than 170 countries worldwide.

Infostealer activity detected by HudsonRock

Compromised Employees: 64

Compromised Users: 3387

Third Party Employee Credentials: 305


External Attack Surface: 114


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@cscglobal.com
MX Records
  • de-smtp-inbound-2.mimecast.com.
  • de-smtp-inbound-1.mimecast.com.
TXT Records
  • brevo-code:93f289e363f8f5ee27b599ce69412ed1
  • google-gws-recovery-domain-verification=42357351
  • apple-domain-verification=XiN3L0je5aGwO4YF
  • adobe-sign-verification=d1856e9dfc1d0dfacf3c6b0bcd1b564a
  • brevo-code:61942c2ee054ab5265a78d06ec4136eb
  • google-site-verification=bR44xxoM8l6qWeP8J5KY8-yjGRyw0ngayiQ_qN8kotI
  • brevo-code:96a41c6d73a3b493e3790f789402b22a
  • brevo-code:0b871975985644473df73dce17148313
  • google-gws-recovery-domain-verification=44223348
  • google-site-verification=K-TB4ZRS1_Xn0KdnIVdIhLca4xZBOCulQaqr8henj6I
  • adobe-sign-verification=7d0f4ee51e8cc8218a0d47de7ad6ecf5
  • mongodb-site-verification=yVC7moEiA8vYgm0kKNzFWh54vnZFhgCi
  • _x7ifm9dj3wk3d2tf3hht44e2ckwiyt2
  • google-site-verification=2pArBQooz7jOEYIlJJd8aIk3bQkzzEDtYm3rFbfqqYc
  • adobe-sign-verification=5b2b13ebabc32a55b4c4af32c203f9d
  • google-site-verification=-KD-hQ117iq2xq0T59Dhtv9nP4D2JHU1JY-WIUQBbdU
  • brevo-code:0c90471082a3b2462dc9671368d4f56f
  • brevo-code:394c0938defd07c7d32264104daa2049
  • brevo-code:f15df8a444d091fbc01d5bed7a695503
  • cisco-ci-domain-verification=5155b7cf4e81dab53704cb8e8bbfec96101a4768a4840fb95ecf3ca57e081f49
  • brevo-code:91c1c04f1ce59b3265ec91944a8343de
  • google-site-verification=Ob6eYGno8ceAOTHHlVlm1R2qNCMNpSGJCrY-v-gwlgA
  • google-site-verification=wKJo0iMF_DdMecpelgRpMgaHIjETpIOS74mawV566Lk
  • brevo-code:67f6623ea0044093109c2520fd2c79e6
  • brevo-code:c914b59e7f282b7bd6be6707d3d410c1
  • brevo-code:ba0a6f95595289aa887adc5b2ef2bcce
  • adobe-idp-site-verification=5325327a-4b7a-46bb-bc1d-f929aa0046e1
  • atlassian-domain-verification=fTuV4RMI2ROPmmpfXvaNTJP2wVZ8wHbIatbyBId5eeZumWuBr1nKxl0iJfK71LJa
  • brevo-code:fe7c2939c9e4dde57d3f5f8afed07fbf
  • miro-verification=489e201f4ac755cb66fe5fae3d4a531f5b473fa3
  • brevo-code:8e6392d950a67d8430ca290610ca6cfe
  • brevo-code:09b3609550913589ba7302525deafc5f
  • _3daqqjnw82p95xy3hcig0406l4xhrh2
  • brevo-code:7ca8cc06dfe6fda15f4ffeb9a0fdb3e2
  • brevo-code:12986ff77994e3b05ad793f9315ca49e
  • brevo-code:42560fbcd317952d1a90f3dbb95f8642
  • mandrill_verify.jpqgR8_udPPbGdibnAGcSA
  • _m7vrrtg99q1x0ehucalf0hkh7r3d0kl
  • brevo-code:e2277458c8e0c736cd799f02d1e64a75
  • cisco-ci-domain-verification=305faf4ed2622c895a0ab9a323c1daa095429bb63746109813da28ff0e0bca4c
  • _alw31bezmifq57qa6derdc8c8fwhokv
  • Sendinblue-code:320d7a0a1776887db9640f8121c59c7a
  • vmware-cloud-verification-fae8eec6-4301-493f-b903-5035577b7d6a
  • brevo-code:9f8cbcbe07537030c9311060a71a96a0
  • UPMMtSA6InOCHobmgB8z+xlQyU8=
  • llama-index-domain-verification-gs2z5n=1gOZhM75DbfBRNoo7v5N7A902
  • brevo-code:4225d9ab9830b3df7f4a6aaf6d554d06
  • _szvmn2edpb704fn9ki7q097t0yurkqu
  • v=spf1 include:spf.mailjet.com include:spf.sendinblue.com include:sendgrid.net include:cust-spf.exacttarget.com include:de._netblocks.mimecast.com include:44151349.spf03.hubspotemail.net include:spf-008a4301.pphosted.com include:spf-008a4302.pphosted.com" " ip4:64.95.144.196 ip4:52.169.188.148 ip4:201.94.128.0/20 ip4:141.194.36.41 ip4:141.194.36.42 ip4:52.22.10.189 ip4:52.70.196.131 ip4:52.71.64.190 ip4:52.71.20.6 ip4:72.4.119.8 ip4:52.205.191.224/27 ip4:104.208.163.42 ip4:213.32.108.33 ip4:141.194.36.43" " ip4:182.18.163.19 ip4:37.157.8.26 ip4:37.157.8.27 ip4:43.228.187.74 ip4:198.181.201.15 ~all
  • _p403623ut54n8hb614inwyyz9urk9k8
  • facebook-domain-verification=wps16fhtfncnugax62f974k93b33m4
  • MS=ms68566304
  • _srldc54e6tnsgl24vaxgdtpyw3uwf1f
  • brevo-code:259bc6f2bd045d00362685c01614cab9
  • brevo-code:25cd1c6b43792ff04d2f58440a857320
Cloud / SaaS Services Detected
Adobe Apple Atlassian HubSpot Mailchimp Microsoft 365 Miro Cisco Mailjet SendGrid Sendinblue Mimecast Proofpoint

Leak Screenshot:

Leak Screenshot