Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2026-05-09 09:15 UTC
Est. attack date 2026-05-08
Country US

Description:

tdstelecom.com TDS Telecommunications LLC, founded in 1969 and headquartered in Madison, Wisconsin, is a leading U.S. telecommunications provider serving residential and business customers across urban, suburban, and rural communities. The company delivers high-speed fiber-optic internet (up to 8 Gigabit), IP-based TV entertainment, and traditional phone services, alongside business solutions like VoIP, dedicated internet, and data networking. With over 1.1 million connections, TDS is a wholly owned subsidiary of Telephone and Data Systems, Inc. (NYSE: TDS), committed to enhancing communities through reliable, innovative communications technology.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 13

Third Party Employee Credentials: 11


External Attack Surface: 3


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • tdstelecom-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • Dynatrace-site-verification=908c0e8b-552b-470f-b099-bcb9b6432ce7__k6tuk3o7bc8pm9p5u0b9t7bmdv
  • v=spf1 ip4:184.60.40.4 ip4:184.60.40.5 ip4:8.43.176.53 ip4:184.60.40.145 ip4:184.60.40.146 ip4:169.145.39.240/29 ip4:12.129.35.0/27 ip4:69.128.72.30 ip4:69.128.72.31" " ip4:69.128.79.137 ip4:69.128.79.137 ip4:69.128.79.171 ip4:69.128.233.224 ip4:69.128.233.131 ip4:69.128.235.161 ip4:69.128.235.139 ip4:69.128.76.59 ip4:69.128.76.19 ip4:69.128.78.106 ip4:69.128.78.105 ip4:156.55.193.212/30 ip4:156.55.203.218/31" " ip4:156.55.203.220 ip4:156.55.205.65 ip4:156.55.205.66/31 ip4:199.200.27.18/31 ip4:199.200.27.29 ip4:199.200.27.30 ip4:206.71.18.20/31 ip4:147.249.4.125 ip4:147.249.4.126/31 ip4:147.249.4.128/31 ip4:147.249.4.130 ip4:198.245.81.0/24" " ip4:184.60.40.4 ip4:184.60.40.5" " ip4:136.147.176.0/24 ip4:13.111.0.0/16 ip4:136.147.182.0/24 ip4:136.147.135.0/24 ip4:199.122.123.0/24 ip4:43.228.187.74 ip4:43.228.185.67 include:rnmk.com include:spf.protection.outlook.com" " include:_spf-dc8.sapsf.com include:_spf.qualtrics.com include:spfhost.messageprovider.com ~all
  • cisco-ci-domain-verification=7e055987e2863166ef39afe86811006a7228ce4a00be06da196e5849b0b9c99a
  • apple-domain-verification=WjLVKrWwYQ091vMW
  • figma-domain-verification=78fd4c60d7385b3f097d0bc6c3bc8c47b29d6682511bc5d24c334ee0daba9954-1755526353
  • docusign=c330de58-c9e3-46fe-b0cd-1dc396cd586b
  • pardot870601=bbad0da669a521e2707c5ee71a54ecc40ce9fb4891e59c528fdc0344d74cb712
  • nintex.634d9a8b1bac21d7499dec05
  • docusign=06ff88f1-8621-452f-8407-acdab256d84b
  • MS=ms94656840
  • atlassian-domain-verification=icmseemfiatrDBGAaPVTJG3ZdnUAHhTuTe7Fybl9v0BZdm61XnQ5FDHuTwAAIkp0
  • canva-site-verification=m1W0YNVGbfxk3Qb4DeRcbw
  • google-site-verification=BQc2wje8k4WPC0BGhlXKU7TF_-bnxQye4w5JWOQtWsk
  • mUyFNJApBB6vGFt6ZSbfV29gulHT1ZVMZNCMjqEYsR36X63uaX0gC4hX87RsXtKcB8SAUcih2cOb3tON++swHA==
  • google-site-verification=BltlL9lio3cjENeNpemeNU8XOy3QdUYUVMgFJ6uooOk
  • sending_domain870601=d821aa3248bb53d30ed535b07b81c9bb191b031d895d5c7ad231a2f85332e210
  • onetrust-domain-verification=a78443066bdf412da42e1a1a5ee36a20
  • atlassian-domain-verification=X8nKvBWwuymxCvfAoBcodgcKebJTnV6lwh4aM3kklhHX44a3FqSLuRqhGhOKUw2L
  • szo0C9lnZC4nrBrsT0PjuMHD8SJDrjdu9QfJ9AOaZYCdKNTZlr60GtHoJnU6xV0ILz9uTkErPa/2CNwI1XnQZA==
  • knowbe4-site-verification=513af60131784e10ef9219916e6675e3
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Salesforce KnowBe4 Cisco OneTrust DocuSign