Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo wilhelmsen.com

Group: Lockbit5

Discovered by ransomware.live: 2026-02-23

Estimated attack date: 2026-02-19

Country: NO

Description:

Founded in Norway in 1861, Wilhelmsen is a global maritime industry group. With the world's lar...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 14

Compromised Users: 280

Third Party Employee Credentials: 66


External Attack Surface: 76


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • wilhelmsen.com@shieldwhois.com
  • abuse@namesrs.com
MX Records
  • wilhelmsen-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:141.147.10.7 ip4:87.253.237.64 ip4:20.73.60.2 ip4:149.72.143.130 ip4:195.1.182.80/28 ip4:121.123.155.242 ip4:77.88.70.138 ip4:152.70.162.25 ip4:132.226.204.117 ip4:129.159.250.38 ip4:193.122.53.174 ip4:149.72.70.241 include:spf.protection.outlo" "ok.com include:_spf.salesforce.com include:_spf.netigate.se include:spf.eye-share.com include:_spf.sndr.no include:spf.mailjet.com -all
  • apple-domain-verification=NcLjA1Cvhrfx2mUZ
  • pardot426922=987477246ca7878a9ebcf7b31929cbe1cab51278e000ea6fe63fdede5a7172d6
  • Probely=006b4279-a7ae-4de3-9ef8-b8e88fafcd0e
  • mgverify=9e86f56d366737dc26b6b3e1e8289f5582d3df0e5724658e6cd9459cd06f1958
  • atlassian-domain-verification=pSZQ5nb0Ia8cjZhNSm33P5JXXiND/7eR7QhuwhbSlfTkRD8aHl61uGj/Yi3PT434
  • 6Dp2Yee9LDULaeDUw4HDjLlhjvEy2DYnOFcs7CoOUPLlagUlB/QZJSI62aZNmQ0oCtfCKd1Rw54/FapPS5uuVA==
  • Foxit-domain-verification=b1c83f5a312364215317a060c50cb0f8
  • d0e2db4f53b640ef905199ec0a102179
  • pardot300991=f1e3802d92485f6464b47f30a619f58eb99b79dc86fe6c32c2612e4f193323c1
  • adobe-idp-site-verification=8636d85e741d6911169bc8fcc5aa3a6d9e8fdcee9dd5a51b8bc0467d55b34eda
  • DomainVerification=0A6QTL9BH53R9RNSNNZO5FHUGGQX5QY96UE5D2X5S4Y6S2NU08WF8LZUZ5K04BWB
  • google-site-verification=BWRxQ3f3Nm_7dNQBKm_uBFHUwX0hwP2s9Fe_fc1QzwM
  • pardot300991=591c78f2005bda54754d776a27b8ca3f062ff8d9702a145efe3489472f781f4e
  • pardot_300991_*=b2580c880aa326eee55c36d743c18cdf6b062164ab10bee7a0f0d2682ff2b119
Cloud / SaaS Services Detected
Adobe Apple Atlassian Salesforce Mailjet

Leak Screenshot:

Leak Screenshot