Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo cavotec.com

Group: blackbasta

Discovered by ransomware.live: 2024-04-19

Estimated attack date: 2024-04-04

Country: CH

Description:

Cavotec is a leading cleantech company that designs and delivers connection and electrification solutions to enable the decarbonization of ports and industrial applications. Backed by more than 40 years of experience, our systems ensure safe, efficient and sustainable operations for a wide variety of customers and applications worldwide. Cavotec’s personnel, located in some 30 countries around the world, represent a large number of cultures, and provide customers with local support, backed by the Group’s global network of engineering expertise.SITE: www.cavotec.com Address : Cavotec SA Corso Elvezia 16 - CH-6900 Lugano, SwitzerlandALL DATA SIZE: ~800gb 1. Engeneering and projects 2. Technical R&D and drawings 3. Accounting and finance 4. HR and personal users data & etc…


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 12

Third Party Employee Credentials: 4


External Attack Surface: 2



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • cavotec-com.mail.protection.outlook.com.
TXT Records
  • 9f0c9mvc6z7npl433wnp1zn00czbh6dj
  • atlassian-domain-verification=su05HZYMz2maweYMPN/O/3VA1RFx70dBoNNaG8WYKbZLBtsarOR9nuPmo9euacpj
  • c8v6m8l7gsxgcgggbkr5h1yz0wd98dnc
  • v=spf1 include:spf1.cavotec.com ~all
  • _e4h0w3g2o90yuws8l5mkok4g0sqvp3y
  • zoho-verification=zb31370343.zmverify.zoho.in
  • sending_domain505751=d7c9a3fec2911bc957734da78a10d273672cad96c816af4d7ff52343425295e9
Cloud / SaaS Services Detected
Atlassian Zoho Campaigns

Leak Screenshot:

Leak Screenshot