Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo RIDERTA.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] RIDERTA.COM refers to the website of the Greater Cleveland Regional Transit Authority (GCRTA or RTA), based in Ohio, USA. It provides public transportation services including bus, paratransit, light/heavy rail transit within Cuyahoga County. Its services help individuals commute around the Cleveland area. On its website, users can access schedules, service updates, fare details, and more.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 5

Third Party Employee Credentials: 0


External Attack Surface: 4


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
  • corlando GCRTA.ORG
MX Records
  • No MX records found.
TXT Records
  • v=spf1 a:dispatch-us.ppe-hosted.com include:icpbounce.com -all
  • google-site-verification=dUay8yTwvUQn260smbq-icQBgu5HFgNnSyjPWYeagyc
  • MS=ms10054706
Cloud / SaaS Services Detected
Microsoft 365 Proofpoint Essentials

Leak Screenshot:

Leak Screenshot