Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo aysa.com.ar

Group: Safepay

Discovered by ransomware.live: 2025-12-14

Estimated attack date: 2025-12-14

Country: AR

Description:

AYSA, formally known as Agua y Saneamientos Argentinos Sociedad Anónima, is Argentina’s largest state-owned water and sanitation utility, responsible for …


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 99

Compromised Users: 16141

Third Party Employee Credentials: 43


External Attack Surface: 120


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • cust25737-1.in.mailcontrol.com.
  • cust25737-2.in.mailcontrol.com.
TXT Records
  • atlassian-domain-verification=B00LmykYg8xlQcAhqF2rW066cexpaKa/rc/vhFQaDaQ2eXwyKBd8dLCKKtSM11Ek
  • leYp4ZRxsARZqnyxrMb+cwAz8EUO3ygHDugENdsrmV7OPFtJCATDmnki9wi5XCsRgnyrDFKsYMrKw+g+gCkIiw==
  • MS=ms51531123
  • MS=ms94673603
  • v=spf1 mx:cust25737-1.in.mailcontrol.com mx:cust25737-2.in.mailcontrol.com a:cust25737-s.out.mailcontrol.com a:mx3.aysa.com.ar a:mxdmz01.aysa.com.ar ip4:200.70.57.67 ip4:200.5.112.100 ip4:52.170.118.235 ip4:52.186.71.165 ip4:52.224.69.247 ip4:40.87.16.59 " "ip4:40.121.62.73 ip4:40.117.198.67 ip4:52.168.138.96 ip4:52.170.220.184 ip4:200.5.112.102 ip4:159.112.241.20 include:musvc.com include:_spf.atlassian.net include:spf.protection.outlook.com ~all
  • atlassian-sending-domain-verification=756a34b3-8cff-4afa-8bcf-3c1c1c0a5181
  • MS=ms32908532
  • cisco-ci-domain-verification=3f3c52b9fc1d6d1d01188917f716ceeeb9dc6538bf4ff0d9389c02914a1c9196
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Cisco

Leak Screenshot:

Leak Screenshot