Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo NHS (press update)

Group: incransom

Discovered by ransomware.live: 2024-05-11

Estimated attack date: 2024-05-11

Country: GB

Description:

After the first post on our blog, we contacted the NHS administration for a month by phone and email urging them to negotiate. In response, we received laughter and statements that they didn't care if we published. Moreover, we contacted the cyber police and received rudeness from these law enforcement officers. And now they're trying to present it like this: Julie White, chief executive of NHS Dumfries and Galloway, said: “This is an utterly abhorrent criminal act by cyber criminals who had threatened to release more data”.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 11

Compromised Users: 93

Third Party Employee Credentials: 3


External Attack Surface: 12



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • england-nhs-uk.mail.protection.outlook.com.
TXT Records
  • EF3E-27A9-2312-1FF4-4069-941C-4362-4BF7
  • apple-domain-verification=cD21DlUFvozbmqh0
  • teamviewer-sso-verification=29f16873e970431fbf501124fc7b7df8
  • globalsign-domain-verification=32F98BF264466C55A24FAD43A8F9D5AE
  • globalsign-domain-verification=7feca880a41428a6f21bef88f4cb44f6
  • globalsign-domain-verification=AE71DDD35D92982542C59A5B6F9A8495
  • globalsign-domain-verification=D8A808F8AF83642A1904D56F19414A02
  • globalsign-domain-verification=aa02b82531cd002dcac94ecb3cde55c2
  • globalsign-domain-verification=d113231605744546537a885921c40df4
  • google-site-verification=uHeC5GkKkDp_FmN2pc3BH0B4YfWiRmolqtr1RMGSuZg
  • _globalsign-domain-verification=-3NnsWnpRchIvnDJFf4X47CdOLLRTz2CtHCRZgVudB
  • v=spf1 ip4:212.250.43.0/26 ip4:212.250.23.64/26 ip4:40.69.37.211 ip4:52.164.249.202 ip4:52.169.21.42 ip4:52.169.238.60 ip4:52.169.76.42 ip4:52.169.90.89 ip4:208.85.48.32 include:_spf.sigmatechnology.cloud include:spf.protection.outlook.com include:spf2.en" "gland.nhs.uk -all
  • 15evvpthm7le0hpafj7gic10pr
  • ZOOM_verify_u1LDSut_TpO38IFZCQvY7w
Cloud / SaaS Services Detected
Apple Teamviewer Zoom

Leak Screenshot:

Leak Screenshot