Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Simon Property Group

simon.com

Group Medusa
Discovered 2025-11-07 18:31 UTC
Est. attack date 2025-10-28
Country US

Description:

Simon Property Group is a leading real estate investment trust (REIT) based in Indianapolis, Indiana. Founded in 1993, it owns, develops, and manages premier shopping malls, outlets, and lifestyle centers across the United States and internationally. The company’s well-known properties include Premium Outlets and The Mills centers. Led by CEO David E. Simon, it focuses on creating high-quality retail and entertainment destinations that attract millions of visitors each year. Despite challenges from online retail, Simon Property Group continues to innovate by combining shopping, dining, and mixed-use spaces, maintaining its position as a global leader in retail real estate. company is headquartered in 225 West Washington Street, Indianapolis, Indiana 46204, USA. 3,000 employees

Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 449

Third Party Employee Credentials: 51


External Attack Surface: 54


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • simon-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 include:spf1.simon.com include:spf2.simon.com -all
  • postman-domain-verification=d552cd9f2b05401a7f8c7934cd6ebd2ffe8dc4cc7cfcd1155352beb3be9da769a3f8904f41c4ce0ef3ed4540788bf26638d2b378d9f4c214c268097941359f0a
  • canva-site-verification=l18BfjecOmCANdM4ym63KQ
  • docusign=ea8a4ccf-8919-4405-b80e-2cad6222da7f
  • _globalsign-domain-verification=SQONiBgTxRVzPPtIHjei_IUGCiAa0KxoVWFw1QfVes
  • postman-domain-verification=c17dbf91c46ff8b969f9e22dca4e6466faf1379acebac6134ae2ddd242b841cb08ff788a242908ef5fdd08b4f77aba43fc6cbcb6e38878ebc5860ee037d84941
  • apple-domain-verification=IvgUFOq_XIWvqrqmKGWtKzG2cTmcSyT4TlpFZbW8Em8
  • google-site-verification=8z-QU0TSJ96_RIQI9C2LO9rE_sTRzJngBVWaxVl2-iQ
  • google-site-verification=DslJlrOwIY7Eq9xjQ-QrGRVmY96VU2KUjZloYfuYEu8
  • anthropic-domain-verification-s04mf7=A0vufhyozBS3pOvJixjvWXVCW
  • _lhmrq00jkel08tnpya25dtyzuw0amxt
  • onetrust-domain-verification=2d4fde0f525a4c0fae7651bbe1d5b8fa
  • fastly-domain-delegation-00338810-Pj05H2hV4G3-2025-03-31
  • google-site-verification=qaOAEpWccWlM1RXTApsY71HqVB4nHsloNxFkffJF4uU
  • 977hw9xmm24ny9bl4qf2qgz27rqjs1xb
  • google-site-verification=gZyAJ5HLGmnXsQQuAqpF86tN6VOsRbjQbUBsK5wfESo
  • docusign=6e20a13c-8006-4010-bfec-c61b6f40a449
  • google-site-verification=ZXOj0-wqdWghdU3OYbSatHvAEQpZYSNASxv1Vczj1wA
  • u7uvbu5f87kgq9l4scbu6gn4ml
  • badge-domain-verification-v2pyax=T2UHDkLU17oTI2BrZf3512S7Y
  • klaviyo-site-verification=SumnKP
  • klaviyo-site-verification=YgnVSm
  • gu5h4pdaaqd3n3df3uhur44f54
  • atlassian-domain-verification=BGKqgs8MARFyU/BBEf6WezKY502UkleqCtBpWro7lv9u35FS1xPn5XieVEH7HsAy
  • facebook-domain-verification=re8bp2og4wl83ni8fml07eqgulbmek
Cloud / SaaS Services Detected
Apple Atlassian Global Sign Anthropic OneTrust DocuSign

Leak Screenshot:

Leak Screenshot