Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-10-03 15:47 UTC
Est. attack date 2025-05-01
Country US

Description:

[AI generated] Instacart is an American company that operates as a same-day grocery delivery and pick-up service in the U.S. and Canada. Customers shop for groceries through their mobile app or website from participating stores. The purchased items are delivered to customers' doorsteps by a personal shopper.

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 20440

Third Party Employee Credentials: 29


External Attack Surface: 102


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafetysupport.aws.com
MX Records
  • alt2.aspmx.l.google.com. Google Workspace
  • aspmx2.googlemail.com. Google Workspace
  • aspmx3.googlemail.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
TXT Records
  • MS=ms97017426
  • jamf-site-verification=p9Wbnn2kRZUgBQpYBDi0QQ
  • cursor-domain-verification-rp3ktc=inR3eiUc2fMt4A7pVZefT5wpf
  • google-site-verification=7611_WcOK7T7iL7mabA6HI3KGxXGGTvCkPnZWr5TRoQ
  • amazonses:3BBByWoEmuIXk1LAEUFZOXNHgY5zKZsu3mmjfxWbAHU=
  • anthropic-domain-verification-6m2fwg=EnNbp6MtM85x8T7ksrU5o6KVl
  • adobe-idp-site-verification=88a28e2f777124eebb7a7ce5fe8a103d9d456a2c66a1a9c612432bbe0e39496f
  • v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all
  • stripe-verification=CE482A6A9D80B6CA836D7CF17F12042B18B528DE43848AE10D395A791EB8D89D
  • box-domain-verification=19bc82774bec9023a502b0c4a843a74702e5d541bd4d3137ee5aca40f125fae9
  • zapier-domain-verification-challenge=26ff505b-3472-4cbb-9be9-0c4ed4248c4d
  • apple-domain-verification=zDx2GGMyj9AA6xFR
  • docusign=78827b9c-2b17-4ce0-9725-e9473b020738
  • 130391aa-f2fe-4ddb-a709-25355840d1fe
  • stripe-verification=91F91A09FB0255B9B345AA85B1664C617F837B9F46A93D3C4A71A6AFD2D9F2E2
  • linear-domain-verification=ibavxcea92yt
  • _saml-domain-challenge.8006e233-cd81-4326-9d8c-2e9dcb18a3c3.71e40736-c163-46aa-a805-6e0566eec7e3.instacart.com=25dff881-952b-490f-9cb6-a5ad2f7054de
  • postman-domain-verification=0cbbba421c946e6fe9966a72101ea8df5705113e70b6441e7d945647c12c4ed4f75519a563add52a67658bf7a828727eaa430f1c132bee20c9fac446a7d8ff13
  • sending_domain1042071=9e404df5f39302ab6abc435441fa1579b650cb26bbebaf36358f288a2be676a6
  • beautifulai-site-verification=bc56a63e-16ff-4476-916a-0fe0e5087ca7
  • stripe-verification=1909B5AFC1B1DAD0F4168044491D82AD84C03ED2095E411954A157C97531C3A5
  • stripe-verification=1eda0bfa88f677b9e202ae4f37c5901cddfa42cf0545a2724f4f20165f767905
  • google-site-verification=QLFaWMd985d3nhg_YTUDf9CcrP7ltRh_dQwlr8fYy5M
  • aline-domain-verification-f0yrm3=gRLFHiK2Er3z3bfk62MHb9ji3
  • google-site-verification=Ltk5AIrbe_rMHFL86zm3lsXhVrEFm3HREQYh9JBbwXg
  • amazonses:eF9tciWVTNgg0t2VX4JqSBUck8ZLgN09GrvpOl7JEQo=
  • sonatype-verification=OSSRH-52569
  • docusign=abe3fcf1-0bbc-45d4-b65d-342f3c7a96dce
  • sending_domain1117133=b0bc1106b460e434fa1b40b1ca6ca9624371b62913614d91b1ac060f65fdcfaa
  • smartsheet-site-validation=9dZDyTRTIeDwsmWjUjROPM7_9VBSzi1o
  • stripe-verification=9bf671cea76998fa3b16861111cf8423b290090c00a3ff76c533c2ac17457930
  • stripe-verification=a4fd934728dd16ed37361b6394256bb3edeca3d3b5e59fa89315c6aa381701a9
  • stripe-verification=baf3475217b29971e2df9e8bbe82eb90932473c41a8bf0076481862fb12c0d04
  • mongodb-site-verification=Lsv4Eqy4WJK0Y1elBMmoI6qVeQnEwTqG
  • google-site-verification=3Pndvzg_zizVpl_rZ2vog13yGQ5km5BeNFkMeSGW1wM
  • google-site-verification=gyVBOuBNTGOhG0NRYK_T95pm3WGBtXkkXMzHj32_oro
  • KAWUHTYVT
  • stripe-verification=ed7124dad8e19a7a1f8dfc5bd595c981653a492a37295d0d9a722223a7a7be14
  • atlassian-domain-verification=GIb04qWVoHC/BEA2IWPJa8QojTO6I+2d7dIEWDYhlaclO1edibLkNVe84EgtVUGa
  • google-site-verification=TpXvLBbJibe769wAHq8k8GPoD-N2SmRNFvt6jDqAR2c
  • stripe-verification=2aeba444d46df4d5855e70081dd4dd22bb368fe1559dfdf6ead668f4fb5d5c6d
  • 4vrtjjps7jdi20ttnamatkfr3l
  • liveramp-site-verification=VfBGvtXkwbyT1oaEmrJaIzN5P00lg4nJg0BcrOORlIY
  • openai-domain-verification=dv-p3HSknX7Fu87PopFXLMlswxw
  • TAILSCALE-6iI40DvmBtm4g20D4UFe
  • stripe-verification=9d326e7be70b964bf272962f401308685a716bc943c5801c17b64d77fceae3af
  • sending_domain959762=e347b3e5ee2e1e51fa130200183a6923a41cf8fde41ae5435cf3545241be6fa1
  • stripe-verification=30ED6FD045596E565303BAF8EB06AD7B6F1503CBF672E5B13F6F397315B2924B
  • _y79zq1f46t21czhb74s6p7t9f4c2m42
  • google-site-verification=MaNxzCl2voO1wnnqcEliRyEodC1Jmuk3tGvD1_w9dX0
  • stripe-verification=2ADD34EB749A7D589CEEDD0E0134A410BC8403EE574B61B45E76387609745715
  • google-site-verification=sXqJTXJPNMK21t3T0NM60sNfZfa6dTYZwR9DF3pd2jQ
  • stripe-verification=5b290a4f24de6f2283e629281196746cddaacad38fb72602f55e4ff5054ca835
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Microsoft 365 Stripe Box Anthropic OpenIA JamF DocuSign

Leak Screenshot:

Leak Screenshot