Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.metlife.com

Group: ransomhub

Discovered by ransomware.live: 2024-12-31

Estimated attack date: 2024-12-30

Country: US

Description:

[AI generated] MetLife is a leading global provider of insurance, annuities, and employee benefit programs. Established in 1868, it offers life, dental, disability, and accident insurance to individuals and groups. Headquartered in New York City, MetLife operates in over 40 countries, serving millions of customers. It focuses on delivering innovative solutions to help clients manage risks and secure their financial futures.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 147

Compromised Users: 7396

Third Party Employee Credentials: 81


External Attack Surface: 147



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
  • hostmaster metlife.com
  • whoisrequest markmonitor.com
MX Records
  • mx2.metlife.com.
  • mx1.metlife.com.
  • mx2.hc1983-11.iphmx.com.
  • mx1.hc1983-11.iphmx.com.
TXT Records
  • stripe-verification=F801EC919FBB4D01B31AC07B367B5487F5FC6048F98127B00F934B80757B9F38
  • SFMC-v-xHifsATOTzHpzzHIWBOl_Zq0ZlsGh12Tujh7hq
  • MS=ms19824334
  • _c36ns9pgyw794wn8hhh6a7hu14s68cc
  • miro-verification=4af63e43eb876c31470b6faf767b1644046ab5d0
  • _ep5wzpowa8tji1lygv53difolzzv659
  • facebook-domain-verification=rx7wl8evvdk3fv5cx911wkwklsir49
  • duo_sso_verification=lmOFE6oJujWqfwYA1wKlUAmdfdcRf3XPvd6HAtsg6rU3GVfbpvIkYBcSurbIaXCX
  • flexera-domain-verification-tffrjryoomkacqcv
  • mozhqNTaCe5yQmagnT6o/p8xHvgKvSVhuOaD1X4kbGLbogrLTP4cjkGegPdRRscvZP+ClaTRAQpQPf6iFP9gHw==
  • v=spf1 include:_spf.metlife.com include:_spf3.metlife.com ~all
  • adobe-idp-site-verification=fc57d3e1346858448d2bcf628217aadbc40e774466e76d0a1780a99255d99ae7
  • SFMC-D0b7aqRgSZF8M4r6SiGn_gymlFcpbBYR5xRY6SQD
  • twilio-domain-verification=758534b1efb07ea5c4bf77f130dc160b
  • SDc+4EOQtfnaUxfyY8URv5amoO0Z65Hk9eks9sDIsl9TOfLNQEblxGLOOltIBwUFRPcOgVusIcGH6ToW9NC1HA==
  • google-site-verification=XOk4GzmAUS8cJyPMbmIamq1MtA23y_SLT2XrlBGtsPo
  • google-site-verification=mnzLM4n-vXShKTOtzTKZWuidirXpOikX6tNdiJcMxb8
  • flexera-domain-verification-guxkdvxgpulkcizw
  • infoblox-domain-mastery=0a7253fd7e76b83fb11e91cab9150698db2d23dda0824d08666e139d5a6495db62
  • canva-site-verification=NSp1rubSzsmhGpmGqRBm8w
  • 537418cde248ae2dfda6516c6b7b404e481f31cd9b7e560f7483d5bc3007fb5a
  • MS=ms74093254
  • hcp-domain-verification=143dc0f7f023aba7cc49c7c034910f2de19f5ec41a639ece0f0a15ec30ff7280
  • 94Fa8tWmklE8h5H_2ub0
Cloud / SaaS Services Detected
Adobe Microsoft 365 Stripe Twilio Miro Flexera Cisco Duo

Leak Screenshot:

Leak Screenshot