Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo doversd.org

Group: Safepay

Discovered by ransomware.live: 2025-11-12

Estimated attack date: 2025-11-12

Country: US

Description:

Dover City Schools is a public K-12 school district located in Dover, Ohio, serving approximately 2,650 students across multiple schools. …


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 12


External Attack Surface: 2


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
  • Licensing doversd.org
MX Records
  • alt4.aspmx.l.google.com.
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
TXT Records
  • v=spf1 ip4:208.67.140.165 ip4:208.67.140.168 include:_spf.google.com include:customerspf.schoolmessenger.com -all
  • 11sku4ghpigqu0djut9jtghbde
  • GFOW0J2LI7FWQ1NK195QDJKVJWRVXNTQQ6MOC2JZ
  • ce7vmvscvk0s181l9f6cuklm8s
  • google-site-verification=k1lotNOp9JYDD4vTeBp01s7QoqnLvbXJwvpA0dJOAVI
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot