Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Norwest Venture Partners

www.nvp.com

Group Sinobi
Discovered 2025-08-15 00:34 UTC
Est. attack date 2025-07-10
Country US

Description:

A top venture and growth equity investment firm, Norwest works side-by-side with the world’s most successful entrepreneurs, providing expert guidance and personalized resources every step of the way. Founded in 1961, Norwest Venture Partners is a global, multi-stage venture capital and growth equity investment firm. The company is headquartered in Palo Alto, California with offices in India and Israel.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 0

Third Party Employee Credentials: 17


External Attack Surface: 0


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • mail60.nvp.com.
  • mail70.nvp.com.
  • nvp-com.snwlhosted.com.
  • mail75.nvp.com.
TXT Records
  • docusign=44ece563-c4b9-4210-b2a7-d4fb627980f4
  • adobe-idp-site-verification=b9dbdc29c0642edb8f672b47a3adf619ad473c4a11844e371f05e02f011b8859
  • anthropic-domain-verification-bamcf3=rlFenjczjTt4sYLtQ8ryNgsZB
  • zapier-domain-verification-challenge=f3268f51-be73-4f8f-b55b-40476b09f2a0
  • fireflies-verification=01KQZQ9XG688DDJ961JA7GTXA2.ffverify.fireflies.ai-request-verification=2026-05-06T22:42:28Z
  • google-gws-recovery-domain-verification=50483565
  • v=spf1 ip4:207.21.121.130/32 ip4:208.97.214.132/32 ip4:208.72.243.152/32 include:protection.outlook.com include:8560290.spf03.hubspotemail.net include:clientspf.backstopsolutions.com include:_spf.snwlhosted.com ~all
  • fireflies-verification=01KP6C7YJKJXQESNQRAHYZFHC3.ffverify.fireflies.ai-request-verification=2026-04-14T16:12:27Z
  • atlassian-domain-verification=u2/NZ11mSI96Fi94NkvpvNQp7xoG3Y4R7QVOytYUYAIgRNYeVJNymW1bbzeoOYdX
  • miro-verification=4ab5eb2d8d90ad51a03d59d57e25b1dbfe096aa0
  • uber-domain-verification=19495f93-99a7-4ac1-84e5-77e2d66a419d
  • canva-site-verification=QgGskah4B2qGI-tveDGm-A
  • u2/NZ11mSI96Fi94NkvpvNQp7xoG3Y4R7QVOytYUYAIgRNYeVJNymW1bbzeoOYdX
  • ZOOM_verify_woU3js_nRHuJ7949KF8DLA
  • slack-domain-verification=uZh4rhJgLkXi4zSVN44dHLmSSi58r1jZNaEVavBO
  • openai-domain-verification=dv-5rs7xTVHifSUuVvZgZC80cm5
  • apple-domain-verification=1Ws9CEUwYtBHKfuO
  • calendly-site-verification=2HF2Vd4mCGlWGWHj0Tjp5qAMoqeWdLqo9FkMIazT2
  • google-site-verification=bW7FtukJb-Ryia_Ygn6-91k9_lntcyRuB50tqfFHYyw
  • TAILSCALE-rRmfuKgxJhFyfVsNYW6d
  • MS=58F1766DE5E6E3900BB1D847546A107881036FE0
  • cloudflare_dashboard_sso=c274a9843cdaf0b813c594fe4e1b3776
Cloud / SaaS Services Detected
Adobe Apple Atlassian HubSpot Slack Anthropic OpenIA Calendy Miro DocuSign Zoom

Leak Screenshot:

Leak Screenshot