Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-10-03 15:42 UTC
Est. attack date 2025-08-17
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

[AI generated] Marriott International is a renowned multinational hospitality company, headquartered in Maryland, USA. Founded in 1927, it operates a broad portfolio of hotels and related lodging facilities globally. Offerings include diverse properties from luxury to economy chain brands. As of today, Marriott has more than 7,000 properties in over 130 countries and territories, making it one of the world's largest hotel companies.

Infostealer activity detected by HudsonRock

Compromised Employees: 198

Compromised Users: 40558

Third Party Employee Credentials: 368


External Attack Surface: 131


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • marriott-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • Dynatrace-site-verification=b018e42d-1bf3-4214-a55d-b6d11d472484__dkbokapmaohqnqf6rjt4vc75d1
  • canva-site-verification=jksL3Zvuljo2ex9weFenew
  • 9ea2de8a-d4af-4255-86f8-22e6410e7a3a
  • h1-domain-verification=3bPxkTRBe4uck7trDLA9BEguQdHUTpEsbin4kgsAepgHSnsi
  • e2ma-verification=5eigb
  • e2ma-verification=zhe3
  • e2ma-verification=t4xeb
  • EMMA-VALIDATION2-22-21
  • e2ma-verification=rzicb
  • amazonses:ycQqj6K4JaTXJZHZIcYKm+rZk3kf0+CDo58LI2UwkR0=
  • infoblox-domain-mastery=078e97082eaa5be71d1011466d456249102dd95393572d0c23d7652a65d4dec5cf
  • NhJc80JClTwLvKuJzmJzVRWhiX7JEubBi8Tegyp1MyGbRSn0bMKddsgokifhxw2JuZ76PZ8qFHYEW9Aa8ykiwQ==
  • adobe-idp-site-verification=b58a812cb8a67904b7b89c5ba71e21242157d93cc4609f572f4d63398d2f1c95
  • amazonses:TdaQ33Ma34JA3mbWth3J30gcPqfDoCkl/gpcDpdk1hM=
  • google-site-verification=Op26MVqGm5ezgYeMJ0t_6ZCjHTtBehaS43CpvlTFkPg
  • e2ma-verification=5nbgb
  • e2ma-verification=i7b3
  • cursor-domain-verification-1fjpt7=Pu1dYBwqsDofgAhFP0N6ME9YW
  • postman-domain-verification=f50031b67f277c87b8d1fc380cdab9ae7c24fd70fe60547b6d37cb0f78bc3573949498c86dd8ca48648b3f2c4c225df73ee99f2dacae3513358a8911124ad0eb
  • e2ma-verification=r4qcb
  • apple-domain-verification=0BpDQkck5deFVztA
  • e2ma-verification=qohib
  • meltwater_sso_20250515
  • cisco-ci-domain-verification=510f4042252171cd62c2992306c3623499318270fcef3f0266e4bc2bc4df9053
  • e2ma-verification=eqqgb
  • smartsheet-site-validation=PYWle4OQif7gvVJpZX6Xo3bdBYQQX8Vu
  • e2ma-verification=pzchb
  • MS=ms72490600
  • bv-domain-verification=0d66f71c181efe6f149b1afc3bf7494520986eddfd13915969aa53da25a4a5f5
  • e2ma-verification=g23cb
  • e2ma-verification=g83fb
  • docusign=a75f5992-a1f4-42fb-b1fb-36850d8e976a
  • docusign=b47573dd-01c3-49a8-9014-26e813e1c8d2
  • e2ma-verification=9ntgb
  • e2ma-verification=rohib
  • e2ma-verification=8oreb
  • e2ma-verification=2m0fb
  • e2ma-verification=hsbcb
  • amazonses:dRwYaeqcRYgOr0nfuNpgfwcye7qC/+W7j9+4l95WmfA=
  • _vo9fuuxfwrimz2thuq6vane5ixcrnre
  • v=spf1 include:spf.marriott.com include:spf.givex.com include:mail.zendesk.com a:c.spf.service-now.com include:spf.protection.outlook.com" " ip4:65.221.12.128 ip4:65.221.12.148 ip4:70.42.227.151 ip4:70.42.227.152 ip4:68.233.76.14 ip4:68.233.76.20 ip4:68.233.76.41 ip4:216.34.69.5 ip4:34.194.251.20" " ip4:41.138.70.80/29 ip4:52.86.138.215 ip4:23.251.231.176/28 ip4:23.251.231.192/28 -all
  • liveramp-site-verification=dphz_fboDvNf-L04XjGWSNpfcEjqykIGaOetpgtRFrY
  • flexera-domain-verification-jbnluuhrebvugcmr
  • onetrust-domain-verification=c8419e55a9f44fd3a2aea1086589b47c
  • facebook-domain-verification=7yktss7qob13nc0gahxo6028udc8ti
  • e2ma-verification=puqeb
  • figma-domain-verification=92316758906766ace0ee6271ca4f1ccf3795fce0f1925f846f4a5ee4c3dd0cfb-1732030374
  • atlassian-domain-verification=zzbKNynGXmBVVjHMpHdfFpEwzGxKV5plDTgGo00mBnx6f3sEd30UmA/w/TPcy9Ai
  • google-site-verification=vGWnWWqZZS-wOwob2dGmMK44ncOOD3s3Vy7mkUR2CQk
  • amazonses:T+PiZncc85hp45Hh5rxnadRc3PqQCxeWhb2Iulxh+HI=
  • DocuSign-JAS-3f8670aa-a7b3-4c80-b87c-c4009cf24fef
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Microsoft 365 Flexera Zendesk Bing Webmaster Cisco OneTrust DocuSign ServiceNow

Leak Screenshot:

Leak Screenshot