Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

coosalud.com

coosalud.com

Group Threeam
Discovered 2026-09-28 18:52 UTC
Est. attack date 2026-09-28
Country CO
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Coosalud EPS (Coosalud Entidad Promotora de Salud S.A.) is one of the major health promotion entities (EPS) in Colombia, primarily managing subsidized and contributory healthcare regimes with multi-million-peso operating volumes. Alongside its sub

Infostealer activity detected by HudsonRock

Compromised Employees: 30

Compromised Users: 4342

Third Party Employee Credentials: 461


External Attack Surface: 94


Exposure Report
by ParanoidLab
21291
Passwords
1280 critical
2104
Cookies
3 critical
Last queried 2026-09-28 18:52 UTC

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusedirectnic.com
  • coosalud.comdnic.jewellaprivacy.com
MX Records
  • coosalud-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • 4223v6gl0oh8811qpqa27hn3oa
  • MS=ms83676188
  • MS=ms13725087
  • ms-domain-verification=43ab4432-12e8-4778-932d-bc40fb1cf750
  • fortinet-fortiphish-site-verification=vWzAP94CViw8Bnno4bC7jN
  • l9pq20tbm6tq3tfc0rmebcus6h
  • v=spf1 include:spf.protection.outlook.com include:_spf.embluemail.com -all
  • 2cl16780t9lp3816mpbsdi0nc8
  • google-site-verification=XBa-3puxVI2y5AJnYB9psj4C3z0O76ABjsck57kupGA
  • google-site-verification=Sax7vfyPPQM9JxOdrjqQyBqINjLRZAdE9wNpqYthyQQ
  • cvr7paan1s7gu89ttmg0s06fg
  • SFMC-XW_QQOPDZ8wM9A-k82AR47KEzXDs_ekd_LMeecMp
  • 7hqekrgbmpfhkc212er43okkcf
  • vWzAP94CViw8Bnno4bC7jN
  • 85C56744A9D886C0FBACF80095DCD819A54DF80CB455D21929C64BE2814B7D1C
  • dd586a26e4db5176d6b2e63efa7bcb
  • cisco-ci-domain-verification=3efeda147dc071e80b6521aa4139b35893860137093d349ca9c386bb0830bf62
  • ca3-db0a37db69fa44179359c8d4f8c480e0
  • google-site-verification=EVMfk8JKVh0p1WT91iXWkz_M9OPGvbRDegW9DDZzCqw
  • hhacts0b8fniri3t193f8s98jq
  • sophos-domain-verification=8dd872a966abea54c4b71619ca41002d483378ec5374345025b7e717b2dd720c
  • fortinet-fortiphish-site-verification=AJ5VkNPpeAkXS7U8PTgfhV
  • 7h5i1ndo3eh8i7ja7r6fn2ecip
Cloud / SaaS Services Detected
Cisco Fortinet Microsoft 365 Sophos

Leak Screenshot:

Leak Screenshot