Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo telekom.com

Group: Lockbit3

Discovered by ransomware.live: 2024-05-06

Estimated attack date: 2024-05-06

Description:

Deutsche Telekom AG, trading as Deutsche Telekom is a German telecommunications company headquartered in Bonn and is the largest telecommunications provider in Europe by revenue. It was formed in 1995 when Deutsche Bundespost, a state monopoly at the...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 27302

Third Party Employee Credentials: 20


External Attack Surface: 30



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • sece.leitstellenservice telekom.de
MX Records
  • mailin32.telekom.de.
  • mailin22.telekom.de.
  • mailin12.telekom.de.
  • mailout32.telekom.de.
  • mailin42.telekom.de.
TXT Records
  • bw=NPbk0jkxzGa2yr9nGIj9Xj9KAHtJy28NdO0SL6PSKMS8
  • v=spf1 include:_spf.telekom.com include:_spf.salesforce.com ~all
  • ZOOM_verify_kRWkqphTgRDVlIbvv9Kiwv
  • docusign=60ddff7f-bdf1-41fc-825f-47c551160b54
  • Dynatrace-site-verification=7f9c8344-163a-4ff1-912a-2d1f48454207__6bd4e4751cupff61isndkhrsrp
  • atlassian-domain-verification=uGLUdpD2IVY19OJG5SQbVpV497SMTPJPSKYbkZRnWtMwczrdbHLwFVATrVgnlCOI
  • adobe-idp-site-verification=22f64faf827865075c1f3f1d814848b67f1e2ebe012796f5b958a206affdcbeb
  • google-site-verification=NH8PPq6gKjlt7EgalZIOxMTdw1FZ3aV2U56HiXUl1F8
  • figma-domain-verification=160013d7cef1653e8d58a5908848cf939b066e8e3f0a88e17c5a9ca33e8220a1-1742993164
  • atlassian-domain-verification=RYDBmArxP6DhrshwBcIZoo3ZF26BwxWI06Enb8LaC7YfF2d8cPno6tILbMv8SCVS
  • google-site-verification=MPZTaBCWqDmQdTohr5tSNZEo9jXQdMnX4ESkpNW_4II
  • mongodb-site-verification=p7YrLhGyLifl1g3RFBE2JvwOuIOdHSkQ
  • webexdomainverification.BSJE=ba47630b-e4fb-43b0-9ef5-403f5d12d26a
  • Fdo6N5s8B8hnnwXO3S5JBjz6vulda6AAiICiY7mR5vHuH3ltRiwWlgoYzeWKMt9F03nDTM+dwj/CiBb/4eDhVQ==
  • ciscocidomainverification=6e2aa122cdd7178b01900ed66d8b507dd30fb2597364b7380809b09fe03a96d1
  • google-gws-recovery-domain-verification=43219657
  • miro-verification=089da153dee3b2bdebb4e4940c914abf39a26035
  • docusign=23f2c4c1-d834-46ae-a026-4519a62c2981
  • docusign=5e3aa268-29b9-4603-aa34-9d44f82c2b6c
  • google-site-verification=DJgHOPXTkscY4YdgC02U_Z17eJIqIzZo2-Z2wGkwiDM
Cloud / SaaS Services Detected
Adobe Atlassian Salesforce Miro DocuSign Cisco Webex Zoom

Leak Screenshot:

Leak Screenshot