Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo thomas-lloyd.com

Group: cactus

Discovered by ransomware.live: 2024-09-17

Estimated attack date: 2024-09-03

Country: US

Description:

<p>Finance<br><br>“ThomasLloyd is a global investment and advisory firm dedicated to leading the necessary process for social and environmental change, focusing exclusively on the financing, construction and operation of sustainable projects in the infrastructure, agriculture and property sectors.”<br><br>Website: <a href="https://www.thomas-lloyd.com/">https://www.thomas-lloyd.com/</a><br><br>Revenue : $66.1M<br><br>Address: 427 Bedford Rd, Pleasantville, New York, 10570, United States<br><br>Phone Number: (914) 495-3630<br><br><mark class="marker-yellow"><strong>Download link #1:</strong></mark> &nbsp;<a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/TLG/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/TLG/PROOF/</a><br><br><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/TLG/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/TLG/PROOF/</a><br><br><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Personal Identifiable Information, employees\executives personal data, corporate confidential documents, customer information, financial documents, corporate correspondence, database backups, etc.</p><p><br><img src="/uploads/ABN_Amro_Project_Platypus_Strictly_Confidential_b7db08d282.png" alt="ABN Amro Project Platypus_Strictly Confidential.png"><img src="/uploads/M_Plater_Certified_ID_b5b30c0a5a.png" alt="M Plater - Certified ID.png"><img src="/uploads/V_Maclachlan_Certified_ID_567ac4eebd.png" alt="V Maclachlan - Certified ID.png"><img src="/uploads/Andreas_Schmitzer_passpot_21abecd4bb.png" alt="Andreas Schmitzer passpot.png"><img src="/uploads/Passport_Rouxle_Rytz_4bd03159dd.png" alt="Passport_Rouxle Rytz.png"></p>



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse ionos.com
  • dataprivacyprotected ionos.de
MX Records
  • thomaslloyd-com01e.mail.protection.outlook.com.
TXT Records
  • v=spf1 include:spf.protection.outlook.com include:mailgun.org include:eu.mailgun.org -all
  • atlassian-domain-verification=WmexGPRBOd16vYsXv1CaRAqOwRes6ODyqYMm8gtCbZ0utnDlI/nCdnIlRNVIFo8z
Cloud / SaaS Services Detected
Atlassian Mailgun

Leak Screenshot:

Leak Screenshot