Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo National Safety Council

Group: medusa

Discovered by ransomware.live: 2025-03-20

Estimated attack date: 2025-03-17

Country: US

Ransom: $ 150,000

Description:

The National Safety Council (NSC) (founded in 1913) is a nonprofit, nongovernmental public service organization dedicated to protecting life and promoting health in the United States of America. National Safety Council corporate office is located in 1121 Spring Lake Dr, Itasca, Illinois, 60143, United States and has 501 employees.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 205

Third Party Employee Credentials: 1


External Attack Surface: 29


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • nsc-org.mail.protection.outlook.com.
TXT Records
  • t/fwwoOTEVuyWcqoliSy4i1yHwNJpax3ngeaDJEmRCgaB+mEMqgH+TnhsDptopO7NAFOE/Gb7W+zssodrP8/Zg==
  • apple-domain-verification=WtVI5F2ns0EbGTcl
  • ZOOM_verify_NynNZcRJSjuNf0nH5FIsrg
  • <<YTR-SDC-LQ8 >>
  • reachdesk-verification=74SQNUmzWdsJs5yvPIIyTzIM0shT3BcBWfpf1GrXYnemoDQK0oObkOH7kEFwEw2R
  • smartsheet-site-validation=Np7Zo7EPM7pxnyl4jJKMPxUHKsPijorC
  • facebook-domain-verification=3amq19kl1hsh0mq3vgjsvcwkcm1nqq
  • Security code: <<YTR-SDC-LQ8 >>
  • JQLbW8Ha2KIJqwZ6SDGiftJh3KUG9M5mAujBsvZRtu8=
  • v=spf1 include:mail.thoughtindustries.com include:_spf.salesforce.com include:mail.zendesk.com include:spf.protection.outlook.com include:oktamail.nsc.org include:spf1.formassembly.com include:sendgrid.net a:smtp1.nsc.org ip4:172.87.48.12 ip4:172.87.48.13" " ip4:172.87.48.14 ip4:172.87.48.15 ip4:172.87.48.228 ip4:172.87.48.230 ip4:172.87.48.231 ip4:172.87.48.234 ip4:172.87.48.235 ip4:168.245.65.171 ip4:4.7.16.128/26 ip4:38.108.186.0/24 ip4:199.87.209.0/24 ip4:4.53.200.128/26 ip4:52.62.199.66 ip4:52.19.0.156 " "ip4:3.97.56.230 ip4:18.233.211.170 ip4:216.35.11.64/26 ip4:64.41.147.64/26 ip4:65.74.175.0/27 ip4:216.55.46.192/26 ip4:207.211.31.0/25 ip4:205.139.110.0/24 ip4:216.205.24.0/24 ip4:170.10.129.0/24 ip4:63.128.21.0/24 ip4:170.10.133.0/24 ip4:185.58.84.93/32 " "ip4:207.211.41.113/32 ip4:207.211.30.64/26 ip4:207.211.30.128/25 ip4:216.145.221.0/24 ip4:170.10.128.0/24 ip4:170.10.132.56/29 ip4:170.10.132.64/29 ip4:207.58.147.64/28 ip4:216.22.15.224/27 ip4:43.228.184.0/22 ip4:103.47.204.0/22 ip4:103.2.140.0/22 ip4:20" "3.31.36.0/22 ip4:170.10.68.0/22 ip4:158.120.80.0/21 ip4:209.182.204.174 ~all
  • 8jzJ5v9WDQui0O0jNZoqvdh2HEChm6bo3GYBEHMHYYNXlSHObJGuwdTsKxrN4joU527U2TxoMfYDVsF0gD+0Jw==
  • LXFrS3lwo4J0ujXeXf9e2l51avMF6Qxdc3uZXRzM62Xn0iyp/2OxKwH1XD22Z0cHqbq12ViPgTQl/I/qgaJxGw==
  • google-site-verification=Q3eTcqiAeqzkcMvq2maw1HHs1F4F4W72iviDx0wQS3Q
  • google-site-verification=nSd_j3LPjbiCCHvpePJiHJ0ns7Yv_vhIpWUENLjDHB4
Cloud / SaaS Services Detected
Apple Salesforce Zendesk SendGrid Zoom

Leak Screenshot:

Leak Screenshot