Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Tech Mahindra

Group: Worldleaks

Discovered by ransomware.live: 2025-06-27

Estimated attack date: 2025-06-27

Country: US

Description:

[AI generated] Tech Mahindra is a leading global provider of IT, BPO and consulting services. Based in India, it is part of the Mahindra Group. With over 125,000 employees across 90 countries, it offers solutions that help clients enhance their business processes. Its offerings include customer strategy, data analytics, cloud infrastructure, and digital transformation services. They work with clients across various sectors including telecom, healthcare, manufacturing, banking and financial services.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 3282

Compromised Users: 5904

Third Party Employee Credentials: 3877


External Attack Surface: 200


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • techmahindra-com.mail.protection.outlook.com.
TXT Records
  • wombat-verification=3KwxVCQV1HEp-aRXRTKKaZ5G0frhk
  • box-domain-verification=4ddd0babd72c2c8598291015e44a80212f87ff497acca03e96c5c854bdbbf043
  • vmware-cloud-verification-3f13823e-3431-4b3f-946c-497a80925af0
  • jamf-site-verification=RKJ23nlNbYXTomhKfn4kFA
  • google-site-verification=3qiu0Ide6c_Gope8k2o9oecD6hKbWmnbjWHc4wp3gMw
  • mou0AlwiUxqJhPjs81cdDSWQ3jsDMRl5Kn8Xe7v3p+y5QoYQbLjW/bQs03KJxVaXKQs/9mlSHCOcXPE6YNifmA==
  • duo_sso_verification=9YXDYXB3qHsNLubjB8bCEvMhIDy00qsW6uYSdi2pxczlp3MZVAvPwXmzpFFPgZV1
  • v=spf1 mx include:spf.protection.outlook.com include:_spf.google.com " " ip4:119.151.8.99/32 ip4:119.151.8.112/31 " "ip4:203.143.187.82/31 ip4:203.143.187.84/30 ip4:191.41.204.80/29 ip4:103.23.24.78/32 " "ip4:103.23.26.70/32 ip4:119.151.20.178/32 ip4:13.126.171.136/32 ip4:119.151.20.179/32 ip4:129.145.20.114/32 -all
  • atlassian-domain-verification=wBrOFASBvgMlndoPMoLnMXMQ0t0IIHBccg5cHWmjXhAG9EC6iB9ECCaYRauSjrH8
  • zoho-verification=zb56422924.zmverify.zoho.com
  • _np1dvjpumbffc7c9bhqyldrvqj6qp5u
  • cisco-ci-domain-verification=43add812b931648ada7b7f1ff1180518ca774678da26842cc0c4522179c9758c
  • mongodb-site-verification=tGHKhQ3sT7vJGNoofFBzim544ND2MBuC
  • NqA107OZxFT3GGSumGoeMFxVsIV03sUyQY5H5nbffSc=
  • atlassian-domain-verification=ryRbflywjrNYa0Tll0MtSRsnxQYflUjz6L3FUhPSPG9kLiLeNdbBPU5j3IbFiUqx
  • google-site-verification=VpIfniqUnwUwajlc0EOcKUJg54-fFSXps7qyE2J13wI
  • _iwdxd3znjvbpor9oxrt7ueu97pre0d3
  • duo_sso_verification=fE7QwooS3gEzoDaYrAw6CDGiMPeAsTJGDsaBgh54a1xpvf0hetU6n6UlZ74dmGXc
  • _2rq3fokmjopqkzp97lazj8o73inhc5h
Cloud / SaaS Services Detected
Atlassian Box JamF Zoho Campaigns Cisco Cisco Duo

Leak Screenshot:

Leak Screenshot