Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo baillie.com

Group: Cactus

Discovered by ransomware.live: 2025-03-12

Estimated attack date: 2025-03-12

Country: US

Description:

<p>Building Materials.<br><br>“The Baillie Group family of brands are providers of high-quality hardwood lumber! Together we are a family of hardwood lumber suppliers capable of providing customers access to a portfolio of hardwood products suitable for any application. ”<br><br>Website: <a href="https://www.baillie.com/">https://www.baillie.com/</a><br><br>Revenue : $130.5M<br><br>Address: 4002 Legion Dr, Hamburg, New York, 14075, United States<br><br>Phone Number: (716) 649-2850<br><br><mark class="marker-yellow"><strong>Download link #1:</strong></mark> <a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/BAILLIE/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/BAILLIE/PROOF/</a><br><br><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/BAILLIE/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/BAILLIE/PROOF/</a><br><br><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Personal identifiable information, сorporate confidential documents, financial data\payroll, legal docs, HR dept data, employees\executives personal documents, corporate correspondence, etc.</p><p><img src="/uploads/Passport_Meyer_Jill_acda6991d8.png" alt="Passport - Meyer Jill.png"><img src="/uploads/Stop_Loss_Disclosure_2_13_24_016574cdc9.png" alt="Stop Loss Disclosure 2.13.24.png"><img src="/uploads/Passport_Jeffrey_S_Meyer_Exp_02082026_fbad2a6d31.png" alt="Passport_Jeffrey S Meyer_Exp 02082026.png"><img src="/uploads/December_P_and_L_5be83db069.png" alt="December P&amp;L.png"><img src="/uploads/Privileged_and_Confidential_Discussion_with_Legal_Counsel_f2497ceca9.png" alt="Privileged and Confidential Discussion with Legal Counsel.png"></p>



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • baillie-com.mail.protection.outlook.com.
TXT Records
  • _h2wptw3by3lcxqewra158eugykfz29p
  • ahrefs-site-verification_d4e81387b4aa45bfb54654099808d28c52d5134f2f390adfef9aeeaed3638997
  • apple-domain-verification=vNSpcIChNRaLIr7F
  • atlassian-domain-verification=8OvdBwMWmq3W6NJSIaRvkX603IVR+YT7qPvjXQY0owe/pnbo27s2q98zQnrhKKWw
  • atlassian-domain-verification=yGv3wUK4lpKV413PnH0IYR0EBPFMTmFkIfBHyPcC3M49lYZuqDDiMEmscWxIjkKa\010
  • duo_sso_verification=XP1NXnfLKWM9XgYublfyll7O4dncPgLHTUH5Wop4ZDuR77h6Kd4I4otQdGCvWer8
  • google-site-verification=hyATHsdASrQmjqRY7HreVWiH8wxGxX5DHiDtgcAqSUg
  • pwm5cwyct5sts3tznr4flhglldqxsbwd
  • v=spf1 include:_spf1.baillie.com include:_spf2.baillie.com include:_spf3.baillie.com include:aspmx.pardot.com include:spf.protection.outlook.com include:usb._netblocks.mimecast.com include:_spf.salesforce.com ~all
  • KeFy3Ww29NHM+z4wupZouDLOmTIqqVBmau+kGpFiXhNWVnBfP4o4468VBac0qN1zaVL/MpeHLx+YO2YEShG6Bw==
  • MS=ms27953240
  • SFMC-7w4Nrqx2_bMHyBceksj96spITH2n9GihVth9ee8u
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Salesforce Cisco Duo Mimecast

Leak Screenshot:

Leak Screenshot