Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

North Country HealthCare

nch.org

Discovered 2025-07-13 07:35 UTC
Est. attack date 2025-07-13
Country US

Description:

Health information for 600,000 patients has been accessed from the North Country Health (NCH) care

Infostealer activity detected by HudsonRock

Compromised Employees: 7

Compromised Users: 126

Third Party Employee Credentials: 4


External Attack Surface: 41


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • sendio.nch.org.
  • sendio.nch.org.
TXT Records
  • cisco-ci-domain-verification=69180a85e3d15ae999843f96a2ab1055b707378cbfdd1b2e67128f8eb4a0cbf0
  • Cyic4pf4mo2pk4muiQjLL5abyl8QFnxoEis2y+EfnnAetAf8VV4HI8tB8jQrpJrDacs74b2POxQtbjCLxn+d3Q==
  • qnpfqt6n926jo6slooqpc25bb1
  • chfqlnm8rs55ehkobokiac1fdk
  • v=spf1 mx a:zixgateway.nch.org a:sendio.nch.org ip4:198.251.26.1 ip4:172.20.10.27 ip4:172.20.10.28 ip4:147.187.10.0/24 ip4:216.46.54.126 a:smtpmor.healthstream.com a:a055769.mx.mailhop.org -all
  • 2tuvddisiuojnp99996kdor1mu
  • MS=ms95831892
  • x&@d0cxdcM@Ix6
  • knowbe4-site-verification=9fd1ee1b1034cf777b877146365cde65
  • MS=ms16904634
Cloud / SaaS Services Detected
Microsoft 365 KnowBe4 Cisco

Leak Screenshot:

Leak Screenshot