Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Balfour Beatty

balfourbeatty.com

Discovered 2025-10-12 00:49 UTC
Est. attack date 2025-10-12
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Balfour Beatty US, founded in 1933 and headquartered in Dallas, Texas, is a commercial construction company that offers services for construction management, general contracting, cost consulting, and design-building.

Infostealer activity detected by HudsonRock

Compromised Employees: 5

Compromised Users: 78

Third Party Employee Credentials: 23


External Attack Surface: 25


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • balfourbeatty-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • Ifspw6czlr21TwROrOFCPjvvK4QcVx+fZN0fcH6xI24aKFKRRNg8Nqu1Q4hSMuLdfFv7gABeW1Dh+Pf3oeOKhQ==
  • balfourbeatty-p-web-1.azurewebsites.net
  • dr9r049864uc5720ms6a16cf9
  • d365mktkey=69lt6qpeoq1o1fn93y26k9dt1
  • ms-domain-verification=47630b83-c09c-4a49-87d6-0932bcf13a05
  • VlZvG7ieFJAaaELIa4wCzxnxGfPLocwZn9HKgvEJ/mdyu1pUeHwvFDkobN0/eDqmSmb0iAgttJYl7ewkU5n7pA==
  • airtable-verification=cc948e98ad37b6669580ad30577a9053
  • d365mktkey=xufUNlcZkX5v5o2KkvEYNvNghB6DssnHJk7UBohPHEAx
  • fa3a0h2moukk12ejoiviav9h9v
  • as=1483625869
  • v=spf1 include:_u.balfourbeatty.com._spf.smart.ondmarc.com -all
  • k1nruut8245k18o9o3a88180ac
  • apple-domain-verification=VUmsdgeEKt1TlkY1
  • google-site-verification=2kBvBmSpqg8m-00RuftalsUtOMH6Z7m0aOQNP1tJPnY
  • h4s8lkhgh4ak9eoadslbqgdea1
  • infor-cloudsuite-domain-verification=HHRKX8PQQTHP28KTPGC3NE4RTL6THFFVZKG6HJKVXPUSK5XJGUQVFXNYB32PNR3F
  • UUGdHVaz
  • qioasksred5ge4mv7jvq3nqr5
  • gj05dojp4qp4fvedoi2tp9jgu9
  • onetrust-domain-verification=aa7adc13621f30c2ac4871560f1d5ae6a3d949ae9d0018c07d74ebac8a1269bb
  • d365mktkey=tpDGRKDirLrVxrxayKR121DAoUZkxre6Q5vYikwBHMcx
  • detectify-verification=db6b8df8a2415bc9d1cf230c6d373c90
  • MS=ms83292348
  • 2rug7h13nqs5fqgrke3m71ke60
Cloud / SaaS Services Detected
Apple Microsoft 365 OneTrust

Leak Screenshot:

Leak Screenshot