Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ingrammicro.com

Group: Safepay

Discovered by ransomware.live: 2025-07-29

Estimated attack date: 2025-07-29

Country: US

Description:

[AI generated] Ingram Micro is a global technology and supply chain services provider. The company, established in 1979, offers a broad range of solutions and services to businesses around the globe, including cloud, mobility, supply chain, and technology solutions. It serves markets including IT, telecommunications, consumer electronics, and others.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 112

Compromised Users: 10360

Third Party Employee Credentials: 364


External Attack Surface: 161


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse key-systems.net
  • abusereport key-systems.net
  • info domain-contact.org
MX Records
  • mx0a-0021cb01.pphosted.com.
  • mx0b-0021cb01.pphosted.com.
TXT Records
  • traction-guest=9bcca760-1607-4774-af0e-af294d5e1321
  • dropbox-domain-verification=086jlfgetx5l
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
  • dropbox-domain-verification=198qppywlg4l
  • dropbox-domain-verification=9q0h16zyatwl
  • teamviewer-sso-verification=fa21f7d5f0f24467a361a1375fdf7456
  • facebook-domain-verification=68gb13903yfa032g1hvoi9or68efqh
  • figma-domain-verification=d5ec9de77f3acd26ae707750d4a00f5c0c161165c72b7ca5f189981a6f22e294-1733417104
  • google-site-verification=0PxZuOVM7IhbgKL3hLz3hB558Jq0nsQwWUSFzlxhN9I
  • docusign=950f3aeb-adf4-4ed9-a83d-5cc1b2d7196f
  • atlassian-domain-verification=0BEP3SAajmOlV9QqKLkYeibAvoDki0tAOgz/fDoj74x5zw47f73GFVr1WYyJCYgo
  • miro-verification=1f063abc162fa427a5c7ac6ed3433a7eeea2bc65
  • docker-verification=07ec3c3d-7cac-44f2-8193-8eece3af0cae
  • vmware-cloud-verification-023dc71b-0a4a-43c0-8412-6361d1a64ee3
Cloud / SaaS Services Detected
Atlassian Dropbox Box Miro Teamviewer DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot