Group:
Incransom
Discovered by ransomware.live: 2025-09-15
Estimated attack date:
2025-09-14
Country:
Description:
Founded in 1907, Rosco, based in Jamaica, N.Y., is one of North Americas leading suppliers of backup camera systems , mirrors , visors , video recording , sensor products, collision avoidance systems and other visual safety solutions to the worldwide commercial vehicle market. For over a century, Roscos vision has remained exceptionally clear. We engineer and manufacture visual safety systems for all types of commercial fleet vehicles. The company is the largest supplier of mirror systems to the North American school bus market, selling to all major OEMs and parts distributors including Navistar/IC Corp., Freightliner/Thomas Built, Blue Bird, AM General, and many others. Our products are designed from real-world knowledge of the challenges that todays drivers face out on the open road. But thats not all. Rosco Vision systems are also designed to help fleet managers run a more efficient operation, fully compliant with all safety rules, regulations, and legislation.
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 3
Third Party Employee Credentials: 1
External Attack Surface:
3
DNS Records:
The following DNS records were found for the victim's domain.
- dataprivacyprotected@ionos.de
- abuse@ionos.com
- roscovision-com.mail.eo.outlook.com.
- google-site-verification=w9TU_9qDU6L1tnPyoSFhdZIT_gC6pzxnzJZvcSrJBT0
- google-site-verification=iXtfF6yfg_nwL76Kk6f3rD8iiwjAoty5awY91f-tCRs
- v=spf1 ip4:143.244.199.125 include:spf.protection.outlook.com include:spf.constantcontact.com include:spf.emailsignatures365.com include:mailgun.org include:_spf.psm.knowbe4.com include:8311978.spf04.hubspotemail.net -all
- MS=1F34CCD67BBE263D5F7AE94365C015C0B1C9C64F
- 1u0k5p2503t9d0v0etnktj8hhp
- MS=ms25924346
Cloud / SaaS Services Detected
HubSpot
Microsoft 365
Mailgun
KnowBe4
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.