Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

thecreditpros.com

thecreditpros.com

Group Icarus
Discovered 2026-06-16 09:50 UTC
Est. attack date 2026-06-16
Country US

Description:

TheCreditPros' Salesforce instance was breached and 263MB of data were taken from it, including: 01_input_fullcards.csv - 51,691 lines of full-info credit/debit cards: Id,First_Name__c,Last_Name__c,Middle_Name__c,Email__c,Credit_Card__c,CCV__c,Exp_Month__c,Exp_Year__c,SSN__c,DOB__c,Street_Address__c,City__c,State__c,Zip_Code__c,Mobile_Number__c,IP_Address__c,Transaction_ID__c,Status__c,CreatedDate 02_contacts_ssn.csv - 847,990 lines: Id,Name,FirstName,LastName,Email,Phone,MobilePhone,HomePhone,SSN_hidden_field__c,Birthdate,MailingStreet,MailingCity,MailingState,MailingPostalCode,Status__c,Bank_Account_Number__c,Bank_Name__c,Bank_Account_Type__c,CreatedDate 03_creditcards.csv - 722,403 lines: Id,Card_number__c,card_number_hidden__c,cvv__c,expiration_month__c,expiration_year__c,Active__c,BIN__c,Issuing_Bank__c,Prepaid__c,CreatedDate 04_leads.csv - 3,598 liens: Id,Name,FirstName,LastName,Email,Phone,MobilePhone,Street,City,State,PostalCode,Status,CreatedDate Pay or leak! Data stolen: PII, Credit cards

Infostealer activity detected by HudsonRock

Compromised Employees: 12

Compromised Users: 291

Third Party Employee Credentials: 23


External Attack Surface: 24


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • thecreditpros-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • yahoo-verification-key=ltPn5za+GMC359eLRrF7DsXSWBoohwoyfpMv6kGRQM4=
  • canva-site-verification=nUJMILFOw3XGflc75teWxQ
  • google-site-verification=fmi63V7ZEYTtSOaFlqUTtEMBRE-zQILPfBoNHNUwIxM
  • v=spf1 redirect=thecreditpros.com.hosted.spf-report.com
  • atlassian-sending-domain-verification=3e0a92a1-2b48-4de0-be12-7cb3447c851b
  • validity-domain-monitoring=LYGaYPo5ZElT6LcVliKFKPU88
  • activeprospect-domain-verification=vqLwFCdgv0edNPpW1cJMTQ==
  • zapier-domain-verification-challenge=ce70216a-db7e-40a8-9535-8f303d83d887
  • yahoo-verification-key=lmo9ijT771zqXW7i627z4M7zoGj2ZgM8aoCVt6vfBCk=
  • _globalsign-domain-verification=CZXYq3vhR95jK23Gi5U2Z7HzvZiw9Wr5fefENhmB6b
  • google-site-verification=oBvbVLq9_lDqGgt4XuQx8q1CKTsxl6EBUCEI22WnyKA
Cloud / SaaS Services Detected
Global Sign