Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

National Railroad Passenger Corporation (amtrak.com)

amtrak.com

Group: Shinyhunters

Discovered by ransomware.live: 2026-04-12

Estimated attack date: 2026-04-11

Country: US

Description:

Over 9.4M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK

Infostealer activity detected by HudsonRock

Compromised Employees: 10

Compromised Users: 8269

Third Party Employee Credentials: 23


External Attack Surface: 111


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mx2.hc2612-17.iphmx.com.
  • mx1.hc2612-17.iphmx.com.
TXT Records
  • bw=WVk8lecSL1wSvabPx6XsDBRjN6N7PX2RfTnWYlkRwgNT
  • p21DeRGccWrXF4st2xyy1hPLBVpO9+Ya4010c1Kt4P1cHNFqWZD5h5DfohbygQXz2Ma7l9dcHtFqBef6ZYV4Nw==
  • _whz1vpn6qv5yhwcy7ez8vxu4i8iumwx
  • atlassian-domain-verification=845JZNWKeTEHg62xWmy8YCOkKI1gD/IWg4w4/HGtqjwazzGP7GgHr9a5Vdhlyvc7
  • ms-domain-verification=2d55fd47-2e5b-41b7-a198-7c6ebace5d19
  • v=spf1 ip4:70.33.172.36 ip4:174.129.192.189 ip4:174.129.8.146 ip4:12.7.225.18 ip4:12.7.225.39 ip4:12.7.224.10 ip4:85.233.200.160/27 ip4:217.117.153.196/27 ip4:50.31.202.32/27 ip4:204.93.133.96/27 ip4:206.51.247.0/27 ip4:65.196.93.7" " ip4:74.179.243.94/32 ip4:172.214.67.207/32 ip4:23.251.237.159/32 ip4:23.251.237.160/29 ip4:23.251.237.168/30 ip4:4.236.81.254 ip4:48.217.23.130" " exists:%{i}.spf.hc2612-17.iphmx.com include:spf.protection.outlook.com include:spf.mandrillapp.com include:spf.salesforce.com include:spf.au.enablon.com include:cust-spf.exacttarget.com include:_spf-dc4.sapsf.com mx -all
  • MS=301545433FA1E4126BB6C72EFB8D592AFA20B4CA
  • _nwtmjqwjxbh8szvpqryc1ieu4ie04us
  • _noyplul4olb0n3bb7dv8ltn93s0bbc9
  • MS=ms76818831
  • teamviewer-sso-verification=493792d9f4304862bd09db7d4b528bad
  • google-gws-recovery-domain-verification=49529359
  • MS=ms13076239
  • google-site-verification=RINi4O6tAsn3wxPf1R89M2SQed-Xyoo-Ri7xDYqNnJU
  • MS=ms65892260
  • ms-domain-verification=1fceff79-0683-4610-9553-7d9d829943cb
  • Dynatrace-site-verification=2b27ef9f-4326-4c67-ac97-db68f75bff42__1h8g3c6tjuii7oqc3v3qvqeq0k
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Salesforce Teamviewer Mandrill