Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo bathfitter.com

Group: blackbasta

Discovered by ransomware.live: 2024-12-18

Estimated attack date: 2024-12-05

Country: CA

Description:

Bath Fitter is a company specializing in bathroom remodeling, particularly known for its custom acrylic bathtubs and shower enclosures. Founded in 1984 by brothers Brian, Wayne, and Glenn Cotton, Bath Fitter initially focused on commercial renovations but has since expanded its services to residential clients, offering a demolition-free approach to bathroom upgrades.SITE: www.bathfitter.com Address : 5187 Papineau Montréal, QC H2H 1W1 CanadaTEL#: (800) 892-2847ALL DATA SIZE: ≈900gb+ 1. Financial data, Payrolls… 2. Human Resources 3. Personal clients and employees data, Home users data… 4. Confidential documents, NDA’s 5. Projects, 3D model Drawings… & etc…


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 1

Third Party Employee Credentials: 1


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • bathfitter-com.mail.protection.outlook.com.
TXT Records
  • twilio-domain-verification=04eca564aa7c9ff52c17a58565148064
  • smartsheet-site-validation=Vp3UN5Rm0C0GC8DmuWtdLw0truw1u3Cf
  • include:_spf.bullhornmail.com
  • ms-domain-verification=d85ca35a-5fda-40c0-82ba-f1880ddeff3e
  • apple-domain-verification=4AG4l6sZVVtWZOiJ
  • google-site-verification=qgSFxs4rFcUaXt-cjZzr7KO4y8JumVF226w-aWJdALY
  • _github-challenge-bathfitter-ent=e862f730d0
  • MS=ms90762738
  • b15598ee-54d1-4f1f-bdd6-96d6cf7caeb1
  • brevo-code:1a2e096cd844620bf8b6fa8e46874a13
  • d365mktkey=exWU9EQ58Ao1nl6CTy4x0TQd1UIkGTbsxDttqCtyXwkx
  • d365mktkey=J1MSRxwQQlbEDD6xi5z5vwUO5GvdliKTykmALXxKRRcx
  • facebook-domain-verification=lg2pw9ygp1fjrolb3ym6389j0yy0be
  • v=spf1 include:spf.protection.outlook.com include:spfa.cpmails.com include:psm.knowbe4.com include:spf.zohomail360.ca include:can.pb-dynmktg.com ip4:75.98.141.228 ip4:75.98.141.238 ip4:208.185.229.0/24 ip4:208.185.235.0/24 ip4:148.59.108.0/23 ip4:148.59." "106.0/23 ~all
  • GOOGLE-SITE-VERIFICATION=A_XUNAV2YNXRCRXMUBY58RKULG5S94S-4PWS6SVESZA
  • ms-domain-verification=caa5b006-f1b0-4262-9a7b-c3aa924e7292
Cloud / SaaS Services Detected
Apple Microsoft 365 Twilio KnowBe4

Leak Screenshot:

Leak Screenshot