Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo thinkmarkets.com

Group: Chaos

Discovered by ransomware.live: 2025-12-08

Estimated attack date: 2025-12-08

Country: AU

Data exfiltrated: 512 GB

Description:

Founded in 2010, ThinkMarkets is a multi-asset online brokerage with headquarters in London and Melbourne and hubs in the Asia-Pacific, the Middle East and North Africa, Europe, and South America.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 6673

Third Party Employee Credentials: 2


External Attack Surface: 97


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • thinkmarkets-com.mail.protection.outlook.com.
TXT Records
  • atlassian-domain-verification=g94DI45GYH5TUF2rjLyq956oekthuUVcQZy8l3BwJ4kgNjVikZmvaZixPYUXG10p
  • b9adde585b984aeb9171
  • google-site-verification=HE_rv6JnouokTneU1xnTEIzHfvNq2REk0xA6c2C9Ef4
  • google-site-verification=IWRmfgI3RuYUvOnfogiZjgV7VZx3KUfOAaLWhDLcwTE
  • google-site-verification=zYLJmdDaCnhEE2rzOS-VKiT7fKY6fbtpr1AcnQZ4qok
  • v=spf1 include:spf.protection.outlook.com include:email-od.com include:mail.zendesk.com a mx include:virtualcn.dmdelivery.com include:_spf.nmstec.net include:_spf.salesforce.com -all
  • _globalsign-domain-verification=iIqfvG67OyzCf74IGKc4jzcnuXGNNUlm24XRaMEkvq
  • adobe-sign-verification=bc2e732965c79591e2d5e41a9c892753
  • aliyun-site-verification=366fbea9-d703-43a1-a254-5f1251adba3b
  • apple-domain-verification=Srlhgg2YSFK1alOl
  • atlassian-domain-verification=5Umc1YWoIRAzaEwnqLYZ08pQYcNU31UuXIYZ4YAWrgIXdBduDQI/9TGUJ0Imh8KY
Cloud / SaaS Services Detected
Apple Atlassian Salesforce Zendesk

Leak Screenshot:

Leak Screenshot