Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Soapeople

Group: Payoutsking

Discovered by ransomware.live: 2026-01-14

Estimated attack date: 2025-11-25

Country: BE

Data exfiltrated: 1.5TB

Description:

[AI generated] Soapeople is a consulting company that specializes in SAP and salesforce implementation to drive digital transformation. They are an accredited SAP and Salesforce partner. With a team of experts, they provide solutions to businesses in areas like ERP, CRM, Analytics, Cloud infrastructure, and more. Their solutions are focused on improving business performance and efficiency.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 3

Third Party Employee Credentials: 2


External Attack Surface: 4


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • legalservices@eurodns.com
MX Records
  • mail02.soapeople.com.
  • mail01.soapeople.com.
  • mail03.soapeople.com.
TXT Records
  • v=spf1 mx ip4:217.111.201.172 include:sharepointonline.com include:_spf.psm.knowbe4.com -all
  • _c6v4shqza7zp6dhugqunk9neqh8e3jn
  • successfactors-site-verification=OTgzNjNmZWEzMmM2ZmFmZGYwZjY2MmFiZGJkZTM2OTM1OGMxOTU2Zjk4ZDllZTFmMGNjZjEwYjEzZjdmMGY4NQ==
  • atlassian-domain-verification=c3tOv9RDpVERCrdq1M4uihEX9/pnbrlWIZUCCapfodz7KHkfBr6pC8pavF5itcmz
  • b3qbXFUxNJ0dIK0Av2vZwoJL2sVtdpUG03xTDiHC9T5wTHtyz6hBBTWiMtUM1DYCmEyZuACZvQuDJD6fvuNKSQ==
  • openai-domain-verification=dv-yDMA9Y1uxcqmo6GsV7wH2ivZ
  • MS=ms87395288
  • c68bb0c7-f883-4c91-bdc3-487054373bff
  • docusign=f5bca5f4-7cfb-47b2-93b6-9345e75c1b5c
  • atlassian-sending-domain-verification=9d776334-c8fb-4848-a78d-0eea6f0375dd
Cloud / SaaS Services Detected
Atlassian Microsoft 365 KnowBe4 DocuSign

Leak Screenshot:

Leak Screenshot