Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-10-03 15:53 UTC
Est. attack date 2025-06-28
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

[AI generated] TransUnion is a global credit reporting agency that provides credit information and analytics services to businesses and individual consumers. It collects and aggregates information on over a billion individual consumers in over thirty countries including "Big Three" credit-reporting agencies in the United States. The data they handle includes credit history, credit scoring, and personal information protection services.

Infostealer activity detected by HudsonRock

Compromised Employees: 6

Compromised Users: 22281

Third Party Employee Credentials: 49


External Attack Surface: 108


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mxa-00030c01.gslb.pphosted.com. Proofpoint
  • mxb-00030c01.gslb.pphosted.com. Proofpoint
TXT Records
  • atlassian-domain-verification=OhHXxTASP58PzZdtjRtShflj0LkhtrIoEKZcj36Cl8vr9mfTPrXbQ/E98t4RIU3g
  • wiz-domain-verification=08404115cff5379ad218fb342997d763c235ea97ac1a82c4d6d6df73a89537e6
  • fastly-domain-delegation-SG3JlbSicvnjUP5-20250211
  • google-site-verification=X5Ss38uDZzpYOYbroWhar77PBX0xSubqDGv6m3VN0yg
  • _mj41e6xfoahuvlex1s161mzpa2sy8r5
  • _2jshdp38sxg5l4l62bv2oxj1vkkwb7h
  • krxDEe0X+yAqz66sAWq9wPUKp9Ez0DQQk8ktPqtZZl3Q3P+wvjDSgrvTzJg5JG7gCCQlKb6TdLXHrGyzR4M23Q==
  • h1-domain-verification=QGQB36EeruNayG5fmBw7xT1xQYtEYuPsrn87wEduAjKHrpiJ
  • 4b429cbc-5707-4079-919a-a12dacd73d9c
  • smartsheet-site-validation=rOtK59moIrg3YLWa4T-l73e6oMuExM1d
  • pendo-domain-verification=IcH-rcbF2-QKKYKXUC8NlzfPJjo
  • 00d5w0000079ffteaq
  • atlassian-domain-verification=jTiLDbBFMAfKwc5ytObqpIM8tsjFH3auTw03PYgNP0oA/LfcRn/LdxpNCVX4ihWB
  • mandrill_verify.ZucqPew7hO7ZodyK8xkWSg
  • miro-verification=807af6d442d45df78d20be0aebef9d41ce80af1f
  • _ecc39lvi8sjfxzwnx6fq2vy20wm0yaz
  • zoho-verification=zb43861743.zmverify.zoho.com
  • google-site-verification=FJQTF2lZI5gSneFs0j12-WBIpWcoiVIRK-J3HSH2880
  • google-site-verification=4lDHDL1hlBdOKIql_1hMgPe0U7P6JMveRHTkpsgGH2Y
  • apple-domain-verification=9HLwYgyGueSb3wtq
  • v=spf1 include:spf1.transunion.com include:spf-00030c01.pphosted.com include:_spf.salesforce.com include:nw000.com include:spf1.masivapp.com include:spf.protection.outlook.com ip4:66.175.245.8 ip4:66.175.249.135 -all
  • box-domain-verification=f5b12dc2d473b532e05af3325951fb2b29dd1c11ffe1907dd302bafd08d16677
  • google-site-verification=ephEuysFxsH6mMiqUJEMhaYAVozhGRfytMBUVhE668w
  • flexera-domain-verification-ddywfwxnutgmcgmy
  • pexip-ms-tenant-domain-verification=value1,01b6fb5d-4a83-4054-bcf3-aa2fa78d1978
  • onetrust-domain-verification=06dbf57bd777463abab5c74d305ab823
  • pexip-ms-tenant-domain-verification=01b6fb5d-4a83-4054-bcf3-aa2fa78d1978
  • infoblox-domain-mastery=642ce8d197c290d511200a53a812f136f4cc20f66d084b646aeb998401fb0b84db
  • google-site-verification=fQhA9XihMKk3bEOWbFuMzvbMoIWn3VV_7dOql4BU31s
  • mixpanel-domain-verify=8a787153-c505-46a3-ae82-9c4855f11218
  • google-site-verification=3sTz13EKg0qGxAgg-gM2ruK1llatf6c0qqPAJM4mURE
  • spf2.0/pra
Cloud / SaaS Services Detected
Apple Atlassian Mailchimp Salesforce Box Miro Flexera Zoho Campaigns OneTrust Proofpoint

Leak Screenshot:

Leak Screenshot