Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Atos (Business Services · France)

atos.net

Discovered 2024-12-28 10:51 UTC
Est. attack date 2024-12-24
Country FR
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

We are Europe’s top choice for cybersecurity, cloud, employee experiences, digital technology & transformation services. We deliver our tailored, secure, and sustainable end-to-end digital solutions worldwide, powering the success and impact of global businesses for their clients and society at large. Tech Foundations is the Atos business line leading in managed services, focusing on hybrid cloud infrastructure, employee experience and technology services. We are a 48,000-strong team with a clear ambition: to apply digital technology to advance what matters for our clients and society at large in 69 countries. With our passionate experts and world-class partners, we design digital solutions from the everyday to the mission critical.Eviden is an Atos business, a next-gen technology leader in data-driven, trusted and sustainable digital transformation. With a strong portfolio of patented technologies and worldwide leading positions in advanced computing, security, AI, cloud and digital platforms, it provides deep expertise for all industries in more than 47 countries. Bringing together 41,000 world-class talents, Eviden expands the possibilities of data and technology across the digital continuum, now and for generations to come. https://atos.net/

Infostealer activity detected by HudsonRock

Compromised Employees: 375

Compromised Users: 1602

Third Party Employee Credentials: 1009


External Attack Surface: 165


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • atos-net.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=E1br6u_-KmcR8RJjna62HarfgmXNXrHJoT8bVcFLebw
  • flexera-domain-verification-xghdwygmrpxngume
  • g7CuF0rKSpUH2wxML5j85hASqdaWfNer
  • v=spf1 ip4:155.45.167.44 ip4:155.45.167.68 ip4:160.92.141.148/30 ip4:160.92.21.196 ip4:160.92.108.230/30 ip4:160.92.140.180/31 " "ip4:160.92.177.1 ip4:160.92.177.2 ip4:160.92.177.3 ip4:193.56.114.164/30 ip4:193.56.114.176/31 ip4:212.170.156.132 ip4:91.103.172.158 " "ip4:62.134.46.8/30 ip4:160.92.152.2 ip4:160.92.186.94 ip4:80.78.5.227 ip4:80.78.0.212 ip4:80.78.5.228 ip4:68.232.145.191 ip4:216.71.152.242 include:spf.protection.outlook.com include:spf.messagelabs.com include:message-business.com -all
  • atlassian-domain-verification=LA8nvrj5U8jKFuoaUtRnuDTi78KzcTEbueohVWm2ia6EUX7bjo6Cnn7Hl0UI/guP
  • docusign=b46f6d98-f426-4f29-8f4d-b335955cbb48
  • mH1Rn9h3riBvfGruJErTrv0fYVRtzm9p
  • atlassian-domain-verification=/dupNWInO19QIbkYWWJSz5GVuuiIfzFcSzW2ZoN8TNd5tbys8RaIX3xdzmIzaaim
  • atlassian-domain-verification=El8OcdEMNPaQ7MnPHFPEuJ7Gw8TUTpa9wHEpTkTJsx4S0wlAGXp7t2yHwnnHzXog
  • 75W5GNu5DuigefEW8cTyXeQgQ5xwm3sn
  • vfGCbKgDaqRBYdSiNf2QnwnfvGR9gpb1
  • hcp-domain-verification=02b3814c3901c1c4e130ce37fa18db5885b3368a519326f78c441ec21aecce9e
  • dell-technologies-domain-verification=atos.net_81483595-b34f-49df-a43b-d25d780094cd_1673701870
  • HXHgh4EVy5CsL6DiFfYvXWfnqRZjutq4
  • atlassian-domain-verification=tQ76vhjoHXPwqCU0wjW5GvdKHbXnczSlRnabiarnNryggbEUVLiPw5mUbInbMN3m
  • apple-domain-verification=DdRWtSXx52XZQIw2
  • j2rwmmLfBfwR0Z6txsQUhPhFT2Ekm1kF
  • adobe-idp-site-verification=fb07f50eac0c1510d27aa1430813d922db386dd78e770b271fa42a198ff8a8e6
  • TAILSCALE-jP0GaibMkEODxakSW47R
  • atlassian-domain-verification=zdbGqIaHMFJflZwOauKWpk765hSGcMv2aTnyo1JNkfKoaK3vncoEq654sitJ20Hy
  • ZgB1NqB5mF2we9wPxMyrnzsAdXr6vHqG
  • 00DAP000008AM5t=1TBAP00000001SL;00DAU00000J7jaP=1TBAU00000001XB;00DAa00000OjSVN=1TBAa00000006bh;00D0Y000000Yuam=1TBbD00000002JZ
  • onetrust-domain-verification=40f14bcc8aa144fd98455a74c1132e90
  • ThhJZNJafdn0pRmgGUHuQwucnPLMxJWp
  • atlassian-domain-verification=dVCdanTAWfkm0nIZmo4DWpy4Dm/WDkXku2DsulBs5qRgKTM2RO/i6UhXpto9agjq
  • duo_sso_verification=4t8R5hblwKoyM0HGpM0dIJkPyTfPx9TFzA0he6wg9L3srzv5H2BvwSIZ7QG4V4KZ
  • 30.07.2025
  • atlassian-domain-verification=/m0KilaUDOLHVeJlP5qrcggnBsoeV170p/GSxccMB0FrIRkwxmQExTnlD29lV1qz
  • crxTQOL0kTBseGMMi/VSblX5q538AvfCEasjsPPDIHUNzT1hix27KSCS9ecoPYyOzyP6JI8btjkeBlSL2kBWeA==
  • _i2ynfa5v7lkipjupx6nnuna9kc6q1a0
  • AUyWFzNeTfCFixwxEfd5sw80AXkt6zdZ
  • MS=ms28265390
  • dBWMPUFR6BRPBt6mapcPQkmsi4eY19m8
  • uDpxaf09NtE151JnMZT9jUkrhyAPLmCv
  • Dynatrace-site-verification=decda4e9-cdcc-4a94-a36e-b120888a7151__jgdu71lsmu0a2b31s6ham7om5h
  • atlassian-domain-verification=ebgA8sZqFwf1M6B9qvnwHJMmdNbxUcPESsr3wS9UtopkUaDgfMGlXq6P778ImZR+
  • google-site-verification=6JDp0c8UnYdygOIU-d9nTSYznqTRsRJHgYNW2mSbRyA
  • MS=ms54076156
  • google-site-verification=UuS20qJHKNSmyQsDKYtJGdoN-BtgtQBVRq8rCWrj5Mk
  • atlassian-domain-verification=ya5SmvkJmafqz57oHy/k/DdujzUAZK6H3VHaLIGO6ERL4P/V2fSrKIdsO1AhgPwI
  • pardot467241=8b9637f73bddcb3c6be4cd464d3b5510c4a641be7b7c4077b8c88286b70e3e3d
  • zscaler-verification-68871494-25022026-pNbPy
  • jwvhJdDeDBFaj9QEdct3xU5ZetmsNaij
  • Z8kEe#DTuEgdicoN8E#q!RdsIg68Ek!YME#r^295vRMBsD0J^iUrMAhIBXK7UnYjH8*h8mhpzas#W9*pu9Wlx^z2v9Vq6gqqL1p
  • flexera-domain-verification-hbwntdyceaoqhrnb
  • onetrust-domain-verification=4a010e7dc8ea4a7684052ffdf496f2d5
  • google-site-verification=pabbvf08v585Vxkvxlod-03UP1678XMFL3rNpCZIYng
Cloud / SaaS Services Detected
Adobe Apple Atlassian Microsoft 365 Salesforce Flexera OneTrust Cisco Duo Zscaler DocuSign

Leak Screenshot:

Leak Screenshot