Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo firstlight.net

Group: lynx

Discovered by ransomware.live: 2025-09-04

Estimated attack date: 2025-09-04

Country: US

Description:

Headquartered in Albany, New York, FirstLight provides fiber-optic data, Internet, data center, cloud, unified communications, and managed services to enterprise and carrier customers throughout the Northeast and mid-Atlantic.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 1


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse tucows.com
  • support firstlight.net
MX Records
  • firstlight-net.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:66.231.205.129/28 ip4:208.84.108.0/22 a:ipspf.firstlight.net include:spf.protection.outlook.com include:et._spf.pardot.com include:spf.constantcontact.com " "include:_spf.broadcloudpbx.com include:_spf.salesforce.com -all
  • google-site-verification=maVVRoOyjEQFrpoTiORNgr_tWN3QVsqhIvPtrwme8wg
  • pardot584403=42c5cced37606ddb48c68b67b5705ef6bca9ee1add1ce2107f299987d7e494ee
  • atlassian-domain-verification=Jyl68xj5Dy6f8dR50w/OEnjsXGskO5Bia6zf7x4KTvKG9/lMGiW7fqJmqVfsvkcL
Cloud / SaaS Services Detected
Atlassian Salesforce

Leak Screenshot:

Leak Screenshot