Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Milliman Financial Risk Management LLC (Milliman, Inc. subsidiary)

milliman.com

Group Akira
Discovered 2025-10-06 15:46 UTC
Est. attack date 2025-09-25
Country US

Description:

Milliman Financial Risk Management LLC is a global leader in fina ncial risk management to the retirement savings industry. Establi shed in 1998, the practice includes over 200 professionals operat ing from three trading platforms around the world (Chicago, Londo n, and Sydney). Milliman FRM is a subsidiary of Milliman, Inc. We are going to upload 260gb of corporate data soon. Client infor mation (clients' financial portfolios, account balances, transfer s and so on), lots of internal operating files, financial and acc ounting files, contracts, agreements, projects, etc.

Infostealer activity detected by HudsonRock

Compromised Employees: 12

Compromised Users: 8

Third Party Employee Credentials: 3


External Attack Surface: 24


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mxa-00195a01.gslb.pphosted.com. Proofpoint
  • mxb-00195a01.gslb.pphosted.com. Proofpoint
TXT Records
  • amazon-business-verification=f09aa3247f32114f354fb87b478f8dfc3e7a45d217196fddd909435361209af6
  • virtru-site-verify=jL7EauMrtZK6cnJYhawkeQUCo3UhqN434nEfA6qf
  • brevo-code:8591bba1993e0473a2b6dea3709f2c78
  • atlassian-domain-verification=UN4cem0sqmBI0CHGJfb5oeXqtNIEq5MXeyvEzwgt7TCioKG8FbFnJ8XR1Lg91SNZ
  • millimanrootredirects.azurewebsites.net
  • onetrust-domain-verification=f2fc5aa0046743c5997d8c40f17bf13b
  • wrike-verification=NjUwNDAyMTpkN2YzZWJmNjcwZGQ1MjBhNmQyZmIzMGQ0MDM1M2FjODRkNTk5YjZlNDMzNWY2YzdiMGQwMmExYzZiYmRiNTA5
  • docker-verification=a29c6a27-0cf1-4ae9-a967-c91441fbeb92
  • amazonses:2kvkjySjRCjEqXjX7Ngu4Djpdp7SAHnJYsmiVkCrTlE=
  • insomnia-validation=3974bbe2b0004b85b23f2fe102695a61bcbfe6f78de652a4b03001f850f1592d
  • pendo-domain-verification=fde55301-f857-4dc2-844b-1e4c3ebea50a
  • jamf-site-verification=QH4Pk058lTY2ZLg08_07Uw
  • v=spf1 ip4:67.231.149.159 ip4:67.231.157.155 ip4:74.116.172.0/22 ip4:63.131.229.166 ip4:38.142.214.74 ip4:34.223.183.171 ip4:135.84.68.123 ip4:67.231.148.44 ip4:67.231.156.33 ip4:63.131.230.28 ip4:38.32.96.218 include:spf.virtrugateway.com -all
  • sending_domain1087562=c39403d30a4a52757a7ed09bcae0d1083e59f5b360a590962c23cdc6723e4288
  • paloaltonetworks-site-verification=c75e459b7eb36c918870d6e89bd2180faf16eee0e265bc1f5885dc08c34b1da7
  • _proof-domain-verification=0369df32-6803-4701-9a13-d1dd9d7dd41d
  • google-site-verification=dWgaBN7VL63bJpmZXjeV_nrJEPNHYdFr6-ZNF_y8pjI
  • apple-domain-verification=ke7CbsHlrFEa6VT9
  • google-site-verification=Xgrw8jvqOYcJwZC6E-9arHsjDzBbfa7H0rEfNp0kUXw
  • pgdms9ot06klvmt8qgqs86ssfp
  • adobe-idp-site-verification=dfc90489eadab9091a1198d46579b97e751e010832a82f2d07df5ef4f8cab79d
  • 3ocufuv3god0fcbth3f1jjbhqq
  • _proof-domain-verification=ad187108-8be0-43eb-abcb-389e47893baa
  • brevo-code:5d440971f8d928dea68a8af6d663006f
  • atlassian-sending-domain-verification=08fc72eb-1ad7-49c5-8a1a-8a04b2379eb5
  • perplexity-ai-domain-verification-wdasbj=YZWvFm1rbDmsjiBPB5iUR5OL9
  • onetrust-domain-verification=7a6dcac2518149cbad4846479adf2743
  • ZOOM_verify_vHJudaJ81W8z6sf2UvsXQn
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Docker JamF OneTrust Proofpoint Zoom