Group:
Akira
Discovered by ransomware.live: 2023-11-09
Estimated attack date:
2023-11-09
Description:
We've obtained about 70Gb data of a group of companies in logistics/energy providing fields named Simons Petroleum, Maxum Petroleum and Pilot Thomas Logistics. Lots of operating files, confidential docs, personal information of employees, NDAs and so on. I'll make an update soon.
DNS Records:
The following DNS records were found for the victim's domain.
- pilotthomas-com.mail.protection.outlook.com.
- kuyCbtjaYrABdsXVB+G9m5EzHiT72EMc8upiSUYY+s6pDsVKin4+bhsbkaM7BLWe6NgT4K6YTAT632gJxgcR0Q==
- cisco-ci-domain-verification=252c426d64349affb2570f342818b5225256c57a7a8860152713a24ad1e7bf21
- google-site-verification=pWHbvipjWuo4Fpr8yYfcHLgbJkowp2jMhbYFvv1vRmU
- adobe-idp-site-verification=d04e0ee0543415a962a2c5d181e4d02fd0837eab5f1368035a2f68ac7efdce58
- apple-domain-verification=xYxHabgRclU4Ny0Z
- v=spf1 mx a ip4:68.109.244.128/26 ip4:67.23.168.0/24 ip4:173.243.134.122 include:spf.usa.net include:spfa.cpmails.com include:spf.protection.outlook.com include:spf.constantcontact.com ~all
- google-site-verification=i0FbiXFsYOZ1L69eB8u-h6CqhsurrVayS-t6Y-vFE0s
- MS=A00871728850DB32549CCD6F0DA494421A102985
- adobe-sign-verification=ed72ce57a8cc6876b5d7563e8455a35
Cloud / SaaS Services Detected
Adobe
Apple
Cisco
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.