Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-12-01
Est. attack date 2025-11-06
Country BE
City Mons

Description:

[AI generated] bpost is a Belgian company that handles the sorting, collection, transportation and delivery of postal services both locally and internationally. Apart from this, they also manage electronic communications, financial transactions, and other related services. bpost operates in the mail sector as well as in the parcel and e-commerce logistics in Europe, North-America and Asia.

Infostealer activity detected by HudsonRock

Compromised Employees: 409

Compromised Users: 9224

Third Party Employee Credentials: 51


External Attack Surface: 125


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • bpost-be.mail.protection.outlook.com.
TXT Records
  • amazonses:7iAR7GRKGpMzcsauZJW/ZGsWD+a9G1flrBqCozM647U=
  • facebook-domain-verification=vuizo8zc9e1o9b9jdaqz7vxmrmez3q
  • d365mktkey=hoVaNyvdfpJLvjZpJNFxqsixxE1z0pQj6RAxxpWwZ3Ux
  • Dynatrace-site-verification=b72374ef-1d86-4eb9-82b9-1e38afdf81dd__r0ncjbiha2s9j0pp57cf1mh08v
  • atlassian-domain-verification=tWp/pKrehseAZgXQ9TWU7lqiUcuVdY4PD5tpGAoOJW2o4voWiv8kGanUV6a/l+W8
  • HARICA-B9ZBt0Ga2KXHtMtxfKo
  • msfpkey=6hun1crjfk5cq6sckag9h2kq
  • amazonses:Q6D+t9X4XKDziqXW1Fj7UwX5tTp9fdDDDbNGzy1JIBw=
  • bnFZdC7m+DuY2spicJLGKvdFbxPJP0knGT7VzobVuZm7/LCpkgXF940NQ3r+zDLND4teFqOCLOS19BqqtFxucg==
  • apple-domain-verification=PsFwMScQitY2pLzh
  • google-site-verification=ZUel8LSiv8IqoeF5I0CcWrtO63yI_SkTWIE__hjmHuE
  • amazonses:kcixaoOpp5achxkQ/XlSGNefHv0VsC4oJH9EFWfQDA8=
  • onetrust-domain-verification=ec2a3bd2980645fa9dbb8476f589eaaa
  • linkedin-site-verification=4eaa943a-93f5-4932-b1c7-b5ed00b8115e
  • HARICA-lA1b27AmhUiYwE3laeI
  • v=spf1 include:spf.bpost.be include:spf.protection.outlook.com ip4:37.59.200.184 ip4:137.74.178.133 include:eu.rp.oracleemaildelivery.com include:ipreomail.com -all
  • amazonses:O9zu9jUJ1ZwFPYSXKFgULrmH9cGWkr8BmYc+zbH14h8=
  • amazonses:pxw3m8FvPcyyDBFLPXvORPHHa20IFMH9dz92XpnOvHQ=
  • figma-domain-verification=132eacf928b230110e53542a677e3a281e4ad8d8b87792ed61166771d77ff9d5-1765799630
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail OneTrust

Leak Screenshot:

Leak Screenshot