Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.portlandschools.org

Group: ransomhub

Discovered by ransomware.live: 2025-03-06

Estimated attack date: 2025-03-05

Country: US

Description:

[AI generated] Portland Public Schools, based in Portland, Maine, USA, is a comprehensive educational institution providing K-12 education to students. The organization offers a conducive learning environment focusing on student achievement and success. It takes pride in its diverse student body and specialized programs catering to each student’s unique talents and interests. With a dedicated professional staff, it imparts quality education to develop well-rounded individuals for the future.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 36

Third Party Employee Credentials: 56


External Attack Surface: 11


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • cisco-ci-domain-verification=672479bab19f0323c8b9a24d17cd546fca226458a56326b3c756d529af7ae917
  • MS=9AD8DC1AC8AE06B13C956145565339B3CCB063E4
  • google-site-verification=EpSV-5UOhuryuFf_Kt-gJoY5Ww5GxhD4ltsMbO45ptc
  • adobe-idp-site-verification=11807fd46fbe345abc0e865a6414770640ba6b4c09a7a6d07ac149608e093b83
  • solarwinds-service0desk-verification=69aab2d96ff7953ef7803fc48a5f3c6c
  • apple-domain-verification=iHNvJhGeKK7TWmLv
  • asv=383e31db1510a94689b46853d0fdf9a1
  • v=spf1 redirect=atzcok9r._spf._d.mim.ec
Cloud / SaaS Services Detected
Adobe Apple Cisco

Leak Screenshot:

Leak Screenshot