Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

National Safety Council

nsc.org

Group Medusa
Discovered 2025-03-20
Est. attack date 2025-03-17
Country US
Ransom $150,000

Description:

The National Safety Council (NSC) (founded in 1913) is a nonprofit, nongovernmental public service organization dedicated to protecting life and promoting health in the United States of America. National Safety Council corporate office is located in 1121 Spring Lake Dr, Itasca, Illinois, 60143, United States and has 501 employees.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 205

Third Party Employee Credentials: 1


External Attack Surface: 29


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • nsc-org.mail.protection.outlook.com.
TXT Records
  • t/fwwoOTEVuyWcqoliSy4i1yHwNJpax3ngeaDJEmRCgaB+mEMqgH+TnhsDptopO7NAFOE/Gb7W+zssodrP8/Zg==
  • JQLbW8Ha2KIJqwZ6SDGiftJh3KUG9M5mAujBsvZRtu8=
  • google-site-verification=Q3eTcqiAeqzkcMvq2maw1HHs1F4F4W72iviDx0wQS3Q
  • ZOOM_verify_NynNZcRJSjuNf0nH5FIsrg
  • <<YTR-SDC-LQ8 >>
  • smartsheet-site-validation=Np7Zo7EPM7pxnyl4jJKMPxUHKsPijorC
  • v=spf1 include:mail.thoughtindustries.com include:_spf.salesforce.com include:mail.zendesk.com include:spf.protection.outlook.com include:oktamail.nsc.org include:spf1.formassembly.com include:sendgrid.net a:smtp1.nsc.org ip4:172.87.48.12 ip4:172.87.48.13" " ip4:172.87.48.14 ip4:172.87.48.15 ip4:172.87.48.228 ip4:172.87.48.230 ip4:172.87.48.231 ip4:172.87.48.234 ip4:172.87.48.235 ip4:168.245.65.171 ip4:4.7.16.128/26 ip4:38.108.186.0/24 ip4:199.87.209.0/24 ip4:4.53.200.128/26 ip4:52.62.199.66 ip4:52.19.0.156 " "ip4:3.97.56.230 ip4:18.233.211.170 ip4:216.35.11.64/26 ip4:64.41.147.64/26 ip4:65.74.175.0/27 ip4:216.55.46.192/26 ip4:207.211.31.0/25 ip4:205.139.110.0/24 ip4:216.205.24.0/24 ip4:170.10.129.0/24 ip4:63.128.21.0/24 ip4:170.10.133.0/24 ip4:185.58.84.93/32 " "ip4:207.211.41.113/32 ip4:207.211.30.64/26 ip4:207.211.30.128/25 ip4:216.145.221.0/24 ip4:170.10.128.0/24 ip4:170.10.132.56/29 ip4:170.10.132.64/29 ip4:207.58.147.64/28 ip4:216.22.15.224/27 ip4:43.228.184.0/22 ip4:103.47.204.0/22 ip4:103.2.140.0/22 ip4:20" "3.31.36.0/22 ip4:170.10.68.0/22 ip4:158.120.80.0/21 ip4:209.182.204.174 ~all
  • apple-domain-verification=WtVI5F2ns0EbGTcl
  • reachdesk-verification=74SQNUmzWdsJs5yvPIIyTzIM0shT3BcBWfpf1GrXYnemoDQK0oObkOH7kEFwEw2R
  • LXFrS3lwo4J0ujXeXf9e2l51avMF6Qxdc3uZXRzM62Xn0iyp/2OxKwH1XD22Z0cHqbq12ViPgTQl/I/qgaJxGw==
  • facebook-domain-verification=3amq19kl1hsh0mq3vgjsvcwkcm1nqq
  • google-site-verification=nSd_j3LPjbiCCHvpePJiHJ0ns7Yv_vhIpWUENLjDHB4
  • 00D5w000004CjqL=1TBUT00000009WL
  • 8jzJ5v9WDQui0O0jNZoqvdh2HEChm6bo3GYBEHMHYYNXlSHObJGuwdTsKxrN4joU527U2TxoMfYDVsF0gD+0Jw==
  • Security code: <<YTR-SDC-LQ8 >>
Cloud / SaaS Services Detected
Apple Salesforce Zendesk SendGrid Zoom

Leak Screenshot:

Leak Screenshot