Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Vereinigte-stadtwerke

Group: Payoutsking

Discovered by ransomware.live: 2026-01-14

Estimated attack date: 2025-11-20

Country: DE

Data exfiltrated: 800GB

Description:

[AI generated] Vereinigte Stadtwerke is a German utility company that supplies electricity, natural gas, and water to its customers. Apart from these, the company also offers telecommunication services including Internet and fixed network. It primarily serves residents and businesses in the Northern Germany region. The company was founded in 2012 as a merger of several municipal utilities to increase efficiency and service quality.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 64

Third Party Employee Credentials: 0


External Attack Surface: 17


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mx01.vereinigte-stadtwerke.de.
  • mx02.vereinigte-stadtwerke.de.
TXT Records
  • v=spf1 a mx a:shop.vereinigte-stadtwerke.de a:www.vereinigte-stadtwerke.de a:mediaportal.vereinigte-stadtwerke.de a:mail.vereinigte-stadtwerke.de a:netzportal.vereinigte-stadtwerke.de a:kundenportal.vereinigte-stadtwerke.de a:gis.vereinigte-stadtwerke.de " "a:kv.vereinigte-stadtwerke.de ip4:91.106.128.247 ip4:91.106.128.232 ip4:91.106.128.231 ip4:213.174.51.84 ~all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot