Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

nepgroup.com

nepgroup.com

Group: Alp-001

Discovered by ransomware.live: 2026-04-08

Estimated attack date: 2026-04-08

Data exfiltrated: 70GB Description: NEP Group, founded in 1984 and headquartered in Pittsburgh, Pennsylvania, offers outside broadcast, studio production, audio and lighting, host broadcast support, and media management services ** WE UPLOADED 10GB As Samples ** ** You Can Download Samples From Leak Page **

Ransom:

Description:

Country: USA Revenue: $2.1 Billion Storage: 70GB Description: NEP Group, founded in 1984 and headquartered in Pittsburgh, Pennsylvania, offers outside broadcast, studio production, audio and lighting, host broadcast support, and media management services ** WE UPLOADED 10GB As Samples ** ** You Can Download Samples From Leak Page ** Deadline: 2026-04-18 17:22:11

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 23

Third Party Employee Credentials: 23


External Attack Surface: 0



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mxa-00246701.gslb.pphosted.com.
  • mxb-00246701.gslb.pphosted.com.
TXT Records
  • teamviewer-sso-verification=b315c838d7fd4562a144623d506b9357
  • smartsheet-site-validation=F8xBuGGGGofK7Wutq-6YLGVspRWzirZ8
  • openai-domain-verification=dv-IAyajponhaqsLuLNo3myJiSd
  • zapier-domain-verification-challenge=f9dbac76-0622-4715-8a5b-205b29b9426f
  • sending_domain1115333=adba75cf42c05eb75d3659c07ca862bfc1c0b9d010da19ab3bb5715ef0ab9250
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
  • 00D5e000001Bks2=1TBRj00000003Vm
  • google-site-verification=mnq9wViY2Gq4tui8ZZLuXCsIhgnxxA49SpR1n3gzx7o
  • google-site-verification=uPCFXXlUAJ4Elxna6Rljg0GOtEubOwPEqQnQgev8a9s
  • knowbe4-site-verification=26b2677e942f1106ff7f4b57f8e78589
  • adobe-idp-site-verification=4f783e5db0fa47b9c80cd2804c17f404669f71b1402575fb4573542c41442ae6
  • zoho-verification=zb32489324.zmverify.zoho.eu
  • apple-domain-verification=zLoaquSaYikW1kWh
  • pardot1115333=73d26fd8d90c33dc0499e2cc054703778b7f7737ecfdf197e027b8607d6cc626
  • atlassian-sending-domain-verification=88b1d7f0-fe21-4749-a0b1-85962ba22332
  • engine-domain-verification=696087
  • dropbox-domain-verification=w6qyo02qkt3e
  • notion_verify_kazATJWGGXeFojmWzaUaKCCnbaBe1xVXVW0s3uP0ay06yEnmQdrsTT0QQH5MWnEXi31VBW
  • jamf-site-verification=mXC12crUW3pzLrujXpKTiA
  • atlassian-domain-verification=m9z3sT4rqMHBcNSH/AUbSEKQfqaK3nrGzrAm9QMgHMF95b2LU0a9mtmVsxgzZCN2
  • parsec-domain-verification=td_2Kb27HD8nZleLkcpZRAcyDz6wFh
  • 1password-site-verification=N6Z6PGGX5BCG5DX6JZIJZ5NO5A
  • uber-domain-verification=bc7b5b73-98c4-4e4e-a6d7-c6ae7a8c8456
Cloud / SaaS Services Detected
Adobe Apple Atlassian Dropbox Salesforce Box Teamviewer JamF Zoho Campaigns KnowBe4 Proofpoint

Leak Screenshot:

Leak Screenshot