Group:
Dragonforce
Discovered by ransomware.live: 2026-03-20
Estimated attack date:
2026-03-20
Country:
Description:
The Unlimited offers a full range of insurance products, including health, auto, legal, and life insurance, designed to provide peace of mind and financial protection to its customers. Founded in 1994, the company strives to challenge the status quo and deliver exceptional value to millions of customers. Its services are designed to support
individuals and families during life’s unexpected moments, ensuring they are never left alone to face difficulties. Focused on meeting the needs of its clients, The Unlimited strives to treat them like family and provide hassle-free service.
Infostealer activity detected by HudsonRock
Compromised Employees: 2
Compromised Users: 56
Third Party Employee Credentials: 2
External Attack Surface:
8
DNS Records:
The following DNS records were found for the victim's domain.
- za-smtp-inbound-2.mimecast.co.za.
- za-smtp-inbound-1.mimecast.co.za.
- zEQ922X5q3CzG+pczANZikWYj15xYzTgm1gVrg+8tXeQ3jLRFltDnsF5c9OAAKoeGBM8kUIWmWxUefwnVSVTTA==
- google-site-verification=ia0st2dbTOpTNQw54FyCebslUkLZe3Yd_P1YkwECm-0
- MS=ms52826304
- zoho-verification=zb71238287.zmverify.zoho.com
- tudev-product.azurewebsites.net
- 4rnr6nmufop2u06j6rh6uvms1t
- google-site-verification=AAMG7SmiHLn-6rtVVMS4Yby7lj-VPIoJQiiy4fFf0dM
- rs1b26u4ta4sibb056ap419ni6
- atlassian-domain-verification=m7LbGDw5rCxRQHUHqtuYA91+iu735pAYOiD9qsM/JSQATgFQ+ZOGsD93uF/S3fxL
- phishingtackle-domain-verification=09974e6e19c9437c86cf722f3ef5ffd0
- have-i-been-pwned-verification=ec49e97d1a48c8374e7e8a89c51df719
- dg69cpbfmqd6du1d0shi5ktgvv
- asuid.theunlimited.co.za
- google-site-verification=Gj9DxCA2hFy_iBSJU_xiM8tw8YCnTIvHbF3_p2O2e4s
- v=spf1 include:_netblocks.mimecast.com include:email.insidedata.co.za ~all
- 27vervijef46pd4pdrs4htfo1m
Cloud / SaaS Services Detected
Atlassian
Microsoft 365
Zoho Campaigns
Mimecast
Have I Been Pwned
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.