Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Sigma

Group: thegentlemen

Discovered by ransomware.live: 2025-09-09

Estimated attack date: 2025-07-14

Description:

www.sigma.fr https://www.zoominfo.com/c/sigma/405955619 diteur de logiciels, intégrateur de solutions digitales et infogéreur de clouds hybrides : le groupe Sigma concrétise votre transformation digitale. Sigma est fière d’être l’une des toutes premières grandes entreprises du numérique à inscrire ses engagements environnementaux, sociaux et économiques dans ses statuts.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 16

Third Party Employee Credentials: 8


External Attack Surface: 11


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • support support.gandi.net
  • 9ba12c1151c3bdac32b963734a5631e2-766584 contact.gandi.net
  • noc gandi.net
MX Records
  • sigma-fr.mail.protection.outlook.com.
TXT Records
  • pardot_153941_*=0f5cf8571164fcd2b8f1c2f3d39dc05f71498b01e527dfb8d96e9987cc997f3a
  • apple-domain-verification=6oREfW0BeghvrVGd
  • ZlGOu7Ttoulqp8Vei7BWQG0Z6sI=
  • atlassian-domain-verification=c4CgMu6OdGePlf3z3iRwuWXvEYFOwkUW+xQKDxAyO25QtFwLlJSvbqOLb6/FNhnF
  • Kj37l6HoowgsGpR0uA8QTlrIiueMVJZo
  • msfpkey=ycyaetiskqpmall07p8itqvq
  • google-site-verification=szIThm4NWPOWFbhZPvHA3LEevZW3VVUVcZSUEzgHkGI
  • have-i-been-pwned-verification=c0ca0ad365817bb5c51df648903da668
  • msfpkey=387rcsn1u364c65ja38ozoehu
  • docusign=7710c515-e202-4dfa-8952-f3d466fc80f4
  • msfpkey=4l8ou5mnu0y62i8w7q0k6w3d9
  • v=spf1 include:spf.mailjet.com include:aspmx.pardot.com include:_spf.activetrail.com include:spf.protection.outlook.com include:spf.joinmyit.com include:_spf.salesforce.com -all
  • google-gws-recovery-domain-verification=43154476
Cloud / SaaS Services Detected
Apple Atlassian Salesforce Mailjet DocuSign Have I Been Pwned

Leak Screenshot:

Leak Screenshot