Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Welthungerhilfe

welthungerhilfe.de

Group Rhysida
Discovered 2025-06-29
Est. attack date 2025-06-29
Country DE
City Bonn

Description:

Welthungerhilfe Welthungerhilfe (WHH) is one of the largest private aid agencies in Germany; politically and religiously independent. More

Infostealer activity detected by HudsonRock

Compromised Employees: 56

Compromised Users: 2

Third Party Employee Credentials: 29


External Attack Surface: 7


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • welthungerhilfe-de.mail.protection.outlook.com.
TXT Records
  • y6czmsyyfn73zzw91z5tccs2c2b72nr6
  • 58p8mi29qad8sanher5445nti1
  • 61k2du9tuiogofpgqq0mj7tefd
  • MS=ms90609458
  • adobe-idp-site-verification=46711e70a6934dc9e568aa7bc6da1c7346b82e87fa13c93a692d3c90150a449b
  • docusign=beee91be-f372-4f1d-8bf8-4dc302455dd3
  • docusign=e9fd8af8-8016-495c-91be-973451168f80
  • eo00ifpf1b6ojue2plc6f3snhn
  • google-site-verification=OkiTTn8LrPmygGqWuX2qYVb1KN06Hp34P6SMFA28mzI
  • google-site-verification=lCSQi03VFP-hQiqg3C_iPY8Ft-_TEfGYtk8ZJ_IwFtI
  • miro-verification=7a9b47e51fec0dc2a0dbb7566b3c682495a81c3f
  • t3ggnj5eq38sl8tk861502vot4
  • teamviewer-sso-verification=bc4ab92c1ea04d64a2d9ff91968a615c
  • v=spf1 mx ip4:80.149.112.149/32 ip4:193.201.168.38/32 ip4:80.149.112.134/32 ip4:78.94.36.190/32 ip4:208.185.229.0/24 ip4:208.185.235.0/24 ip4:148.59.108.0/23 ip4:148.59.106.0/23 ip4:195.127.237.225/32 ip4:195.127.237.228/32 ip4:195.127.36.228/32 ip4:80.14" "9.112.137/32 include:spf-a_topdesk.welthungerhilfe.de include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
Adobe Microsoft 365 Miro Teamviewer DocuSign

Leak Screenshot:

Leak Screenshot