Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo cphcorp.com

Group: incransom

Discovered by ransomware.live: 2025-09-04

Estimated attack date: 2025-09-04

Country: US

Description:

CPH is a full service architectural and engineering firm providing design for public and private sector projects. The multi-disciplinary team includes architects, engineers (civil/structural/traffic/transportation/electrical/mechanical), planners, landscape architects, surveyors, environmental scientists and construction administrators. CPH works throughout the United States and the Caribbean, completing projects that include water and wastewater treatment, collection, and distribution systems, complete streets, roadways, parks and recreation, and commercial / industrial complexes. Employees: 257 Revenue: $44.1 Million Industry: Architecture Phone Number:(407) 322-6841


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 0

Third Party Employee Credentials: 2


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • MS=ms61785958
  • Target: 0ed1fe018af4e7580afda64b6f9b422cbed86418be
  • sophos-domain-verification=4532d08864d44406320b34a93257539c5a24279e
  • uber-domain-verification=6cc403ad-dfcc-40c2-b00f-b31967c2682b
  • v=spf1 a mx ip4:12.32.147.224/29 ip4:70.46.31.164 include:us._netblocks.mimecast.com ~all
  • zscaler-verification-36377131-6062025-7GNw9T
  • MS=ms57870683
Cloud / SaaS Services Detected
Microsoft 365 Mimecast Sophos

Leak Screenshot:

Leak Screenshot