Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

laalliance.org

laalliance.org

Discovered 2024-04-19 11:24 UTC
Est. attack date 2023-09-11
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

More information in our telegram channel https://t.me/snatch_team Persons responsible for data leakage:Dan Katzir : President and Chief Executive Officerhttps://www.linkedin.com/in/dan-katzir-9711b41https://facebook.com/dan.katzir.14dk@broadfoundation.orgdankatzir@yahoo.comdankatzir1@gmail.com+13233765674+13109545091+13236544025;Desmond Lovell : VP of Financehttps://www.linkedin.com/in/deslovellhttps://facebook.com/desmond.lovelldes.lovell@gmail.comdesmond.lovell@greendot.orgdlovell@laalliance.orgdeslovell@yahoo.com+12132559443+14242742310+15086310290;Alexis Basaldu : Regional Director of School Operationshttps://www.linkedin.com/in/abasaldualexis.basaldu@gmail.comabasaldu@collegespring.orgalexisbasaldu@gmail.comalexis.basaldu@gmail.comabasaldu@stem-prep.orgagrossman@laalliance.org+17608453660+12133276694+17605096774;Sonya Davis : Dean Of Culturehttps://www.linkedin.com/in/sonya-davissdavis3@sbcsc.k12.in.us+15743006940+13239204388;Tarah Barth : Director of Leadership Developmenthttps://www.linkedin.com/in/tarah-deboer-barth-818a8b2bhttps://www.facebook.com/tarah.deboertbarth@laalliance.orgtarahfaye@gmail.com+13609279301;Charla Everhart

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 58

Third Party Employee Credentials: 14


External Attack Surface: 11


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • alt2.aspmx.l.google.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
  • alt3.aspmx.l.google.com. Google Workspace
  • alt4.aspmx.l.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
TXT Records
  • csverification:IE58o62vasqRuDQ49WuI2UyUnYB0rsDTCy06WQgo
  • google-site-verification=ypS3-NS2LXXwmcKpzFrUPRL2FmADgTLSk1WQmy6-F9k
  • jamf-site-verification=BBWT1cQglP4Zg87txTIh0Q
  • v=spf1 ip4:64.183.38.254 ip4:64.183.38.243 ip4:64.183.38.244 ip4:64.183.38.246 ip4:64.183.38.242 ip4:64.183.38.245 ip4:15.197.175.4 include:_spf.google.com include:email.freshdesk.com include:mailgun.org include:servers.mcsv.net include:mail.ze" "ndesk.com include:e2ma.net include:spf.constantcontact.com include:blackboardconnect.com include:mg-spf.greenhouse.io ~all
  • ZOOM_verify_0ZfXj3jioWCou5vmaP1H8j
  • brevo-code:04c1608a6f1163227513fc8772b6a8fe
  • brevo-code:e1121a5c99c1ad396f86334cb626f253
Cloud / SaaS Services Detected
Brevo JamF Mailchimp Mailgun Zoom

Leak Screenshot:

Leak Screenshot