Buy Me a Coffee

This space is available for sponsoring Ransomware.live Contact us to sponsor this space

Logo mcleanmortgage.com

Group: Blackbasta

Discovered by ransomware.live: 2024-11-28

Estimated attack date: 2024-10-17

Country: US

Description:

McLean Mortgage Corporation is a mortgage brokerage based in Fairfax, Virginia, specializing in various loan products to assist clients in achieving home ownership. Established in 2008, the company has been operational for over 16 years and offers services across multiple locations.SITE: www.mcleanmortgage.com Address : 11325 Random Hills Road Suite 400 Fairfax, VA 22030 United StatesTEL#: (571) 405-2527ALL DATA SIZE: ≈1tb 1. Accounting 2. Financial data, Loans, Payrolls, Tax 3. Human Resources data 4. Confidential data 5. Customers, Clients personal docs 6. Personal documents users and employees & etc…


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 15

Third Party Employee Credentials: 0


External Attack Surface: 7



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • mcleanmortgage-com.mx1.arsmtp.com.
  • mcleanmortgage-com.mx2.arsmtp.com.
TXT Records
  • MS=ms79297558
  • google-site-verification=4TaIxjb-1jtLdEyKUbXUbh6vTwen8VUXmYzcEp1PlE4
  • C9WP502ZE7U34EEMME5D440A3SPE7PK995YC5PGX
  • v=spf1 a:mail.mcleanmortgage.com a:mail.appraisalfirewall.com include:mcleanmortgage-com.spf.smtp25.com include:_spf.mailspamprotection.com ip4:74.201.71.35 a:smtp1.fics.com include:spf.exclaimer.net include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot