Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo WORKFORCESOFTWARE.COM

Group: Clop

Discovered by ransomware.live: 2026-01-25

Estimated attack date: 2026-01-25

Country: US

Description:

[AI generated] WorkForce Software is a leading global provider of cloud-based workforce management solutions. The company’s WorkForce Suite adapts to each organization’s needs—no matter how unique their pay rules, labor regulations, and schedules—while delivering a break-through employee experience at the time and place work happens.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 23

Third Party Employee Credentials: 1


External Attack Surface: 14


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • workforcesoftware-com.mail.protection.outlook.com.
TXT Records
  • bw=6eccwH8crBXkU59dUk0rs0JviSwYPSwCgZD1o8A2bDRJ
  • apple-domain-verification=6opfhY6oar2qe1OO
  • miro-verification=b71272618995b93a5d7e94a084288b3870a5945d
  • google-site-verification=RuNMrV_ys8ws_KMZBLc8TjVBywHNKMn00Kue4zyLDUU
  • google-site-verification=H3PGgMk99iphmqTxFnIBjanCyTur_CxYY1THLpvGAM0
  • google-site-verification=2W-l9MnLJrc12JSzL2rQCBEG9Hv6gyRdPM5amnwOOSY
  • PD3Xm3yiJmrG/vaPUkzA7Gh0JWiCliiXLLenUIsuEdGQT+TMa0uoyaSCrRJwjT71AIjsFhU4s3grGgFDD3VABw==
  • atlassian-sending-domain-verification=1796a254-c089-4225-a217-53608e7660cd
  • Dynatrace-site-verification=e5a9cfc6-5e80-4a78-bd53-5f293d1b314e__nbhg6mekoggfc63fv82oogj2g1
  • onetrust-domain-verification=4852ca1587b649b886a44cfe2aa0ad4b
  • 6d52a947-c627-4438-8a00-db3bd4fd1b61
  • docusign=b35bec67-37b4-4c08-a9e8-4b24c4a14f61
  • status-page-domain-verification=v2hv5n4w8ybk
  • 91eao1e04nilsgbdglpn3l7v0g.
  • ipg3vfsqgt0hteud51cikt2efm
  • atlassian-domain-verification=ANiLig3RBrl7g2pUxFNLUeMYagL9whdXruCpz2LQW7yTbrQmHD1nhwNAltzprnq4
  • ca3-cfd047edc7174f5297c0a82dd277e4ed
  • vXPcqDYGZV0pJGQuB3RMBJmpKrO8w9MSdvRzdzYNRMfRPweQ2iUptM8UUvp2YuS57x8rnFf0jbX6h7KRc4SwFQ==
  • status-page-domain-verification=kvpj13kf0vgl
  • miro-verification=64dc31688e02326525402fc3b986e77752e0a3d6
  • v=spf1 ip4:62.32.112.160/27 ip4:129.146.91.38 ip4:110.175.9.230 ip4:74.122.248.0/21 ip4:77.107.114.86 include:docebosaas.com include:stspg-customer.com include:spf.protection.outlook.com Include:et_spf.pardot.com Include:_spf.salesforce.com include:relay" ".mailchannels.net -all
  • logmein-verification-code=33397018-3b42-4b09-b43f-3032f1078fc3
  • 9l8VUUgHmz8Lo/ofeR++qTghAUdTjem7cBL9SNsRF+nSfczozYPygZxGmTYal6ZuF8gRw26wxDNMSpEZzMWFkw==
  • slack-domain-verification=ruDb0ZXofNddSi5quXvxf3bUOWk8GR7IcuYRJy7H
  • google-site-verification=PxIYUIEoWed2qZ7SifyK0wvg8sQC56ZAwqbN51EIjNk
  • pardot_213062_*=0d63131e6c99450aac0c04911d6b297697a09cfbfb2f6ab050f1abdb4d87e80d
Cloud / SaaS Services Detected
Apple Atlassian Salesforce Slack Miro LogMeIn OneTrust DocuSign

Leak Screenshot:

Leak Screenshot