Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo usdaw.org.uk

Group: Safepay

Discovered by ransomware.live: 2025-12-29

Estimated attack date: 2025-12-29

Country: GB

Description:

Usdaw — formally the Union of Shop, Distributive and Allied Workers — is one of the United Kingdom’s largest and …


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 10

Third Party Employee Credentials: 0


External Attack Surface: 4


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • usdaw-org-uk.mail.protection.outlook.com.
TXT Records
  • google-site-verification=ud8gu6-P2WpNWlCblmZJuSfflsTBOli0LYFTw1fm9w4
  • access-domain-verification=d06b6fc04727e953b0da1d7b458dc79833053569c53d78e1816fc40d5e8b22dc
  • ca3-e52174fdf9174b65a29ab84b5a1642bb
  • google-site-verification=kyMPEKEaigf4XtCh4uV3GpW6oXgFBQvyFvHO6Bycjmo
  • MS=ms28990621
  • bADyBD11aTpSZZU6laoWIQH3PQoqxo0Iby8jNbNs1uNnHEG5gPCtKWF2aMx6Cm/G/SUazqFdyymY9mp/qc530w==
  • ZOOM_verify_Hl1AhffzfE7xUJtzZ17gkK
  • apple-domain-verification=IJvLvu37X6zQl8A3
  • v=spf1 mx a ip4:83.98.51.106/32 ip4:83.98.54.8/32 ip4:83.98.54.26/32 ip4:85.115.54.190/32 ip4:83.100.128.0/24 ip4:94.72.211.0/24 ip4:83.98.54.4/32 include:spf2.accessacloud.com include:spf2.usdaw.org.uk include:spf.ssmx.net include:spf.protection.outlook." "com include:spfa.cpmails.com -all
Cloud / SaaS Services Detected
Apple Microsoft 365 Zoom

Leak Screenshot:

Leak Screenshot