Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Aman Resorts (aman.com)

aman.com

Discovered 2026-04-19 18:07 UTC
Est. attack date 2026-04-18
Country SG

Description:

Over 500k Salesforce records containing PII have been compromised. Pay or Leak. This is a final warning to reach out by 21 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 30

Third Party Employee Credentials: 81


External Attack Surface: 18


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • eu-smtp-inbound-1.mimecast.com. Mimecast
  • eu-smtp-inbound-2.mimecast.com. Mimecast
TXT Records
  • apple-domain-verification=LKPHflPrUzsXsHix
  • facebook-domain-verification=vgvfirf4ipx3pv35wholmkyextb1bq
  • smartsheet-site-validation=lGcGtCqA1IR4wcRVrJgtZEx0Y5dNU54z
  • onetrust-domain-verification=7a33296a5d0a4b2fbe65d40d91d1aaa6
  • _globalsign-domain-verification=6Vj5RE_9qAjlRUu7Gle37bpQndNq3qoCeMUOjS2Czv
  • S4jPXnjCN7sszeNXR1w4PX3El+cYXPIDKChYZBqRyfQWjcyupAJGNQGZQ2rbNo1OBDxq19DK6nN+da97eUAKgg==
  • cisco-ci-domain-verification=524fc13c9905c5b46432426400ba1e366811f0ab6e898a7575ff6255970c96d
  • v=spf1 include:eu._netblocks.mimecast.com include:spf.protection.outlook.com include:_spf.peoplevine.net include:nextguest.app include:autotask.net include:_spf.salesforce.com ~all
  • 7h51j3ml2dr3d93cl72cc4zryq12k5rg
  • x4kb1wb9086qc75mvwy447tkbthgk971
  • 0ed1fe018a061bf093f83941918007b0392c3397f6
Cloud / SaaS Services Detected
Apple Global Sign Salesforce Cisco OneTrust Mimecast