Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo NHS Alder Hey

Group: Incransom

Discovered by ransomware.live: 2024-11-28

Estimated attack date: 2024-11-28

Country: GB

Description:

Evidence of large-scale data Patient records, donor reports, procurement data are indicated Information available for 2018-2024


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 3

Third Party Employee Credentials: 4


External Attack Surface: 6



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • alderhey-nhs-uk.mail.protection.outlook.com.
TXT Records
  • sophos-domain-verification=43f46d992d041de582895626cd71e7468b9ae963c9bb6637561c5903327de80e
  • v=spf1 include:spf.protection.outlook.com -all
  • 76e9a6c2-3e34-49a8-a876-ec628f5a342a
  • 80QMLQ183LEBLO2H4B7I7NKAB7
  • ot94ar6v7v19kmtspokscnr54a
  • apple-domain-verification=vl1FILEB64hGCjVV
  • MS=443A30AD888C5FFC224B5D858EA8B9B69C57A14F
  • google-site-verification=cToyxD6N16uj5xQZHHJI5UrOPlcJuX0PjG8Khnrxs-A
  • a58kpORpAHvP86McanO5tJtCF8fmOpu62t2G/18U8rNv063kdqG/5WW1Esyrnl/ueJ3ojpBWDu2vX5Or5oUq0Q==
Cloud / SaaS Services Detected
Apple Sophos

Leak Screenshot:

Leak Screenshot