Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Tech Mahindra

techmahindra.com

Discovered 2025-06-27 21:45 UTC
Est. attack date 2025-06-27
Country US

Description:

[AI generated] Tech Mahindra is a leading global provider of IT, BPO and consulting services. Based in India, it is part of the Mahindra Group. With over 125,000 employees across 90 countries, it offers solutions that help clients enhance their business processes. Its offerings include customer strategy, data analytics, cloud infrastructure, and digital transformation services. They work with clients across various sectors including telecom, healthcare, manufacturing, banking and financial services.

Infostealer activity detected by HudsonRock

Compromised Employees: 3282

Compromised Users: 5904

Third Party Employee Credentials: 3877


External Attack Surface: 200


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • techmahindra-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • duo_sso_verification=9YXDYXB3qHsNLubjB8bCEvMhIDy00qsW6uYSdi2pxczlp3MZVAvPwXmzpFFPgZV1
  • NqA107OZxFT3GGSumGoeMFxVsIV03sUyQY5H5nbffSc=
  • google-site-verification=3qiu0Ide6c_Gope8k2o9oecD6hKbWmnbjWHc4wp3gMw
  • _np1dvjpumbffc7c9bhqyldrvqj6qp5u
  • box-domain-verification=4ddd0babd72c2c8598291015e44a80212f87ff497acca03e96c5c854bdbbf043
  • zoho-verification=zb56422924.zmverify.zoho.com
  • mou0AlwiUxqJhPjs81cdDSWQ3jsDMRl5Kn8Xe7v3p+y5QoYQbLjW/bQs03KJxVaXKQs/9mlSHCOcXPE6YNifmA==
  • atlassian-domain-verification=ryRbflywjrNYa0Tll0MtSRsnxQYflUjz6L3FUhPSPG9kLiLeNdbBPU5j3IbFiUqx
  • cisco-ci-domain-verification=43add812b931648ada7b7f1ff1180518ca774678da26842cc0c4522179c9758c
  • google-site-verification=VpIfniqUnwUwajlc0EOcKUJg54-fFSXps7qyE2J13wI
  • jamf-site-verification=RKJ23nlNbYXTomhKfn4kFA
  • v=spf1 mx include:spf.protection.outlook.com include:_spf.google.com a:b.spf.service-now.com a:c.spf.service-now.com a:d.spf.service-now.com" " ip4:119.151.8.99/32 ip4:119.151.8.112/31 " "ip4:203.143.187.82/31 ip4:203.143.187.84/30 ip4:191.41.204.80/29 ip4:103.23.24.78/32 " "ip4:103.23.26.70/32 ip4:119.151.20.178/32 ip4:13.126.171.136/32 ip4:119.151.20.179/32 ip4:129.145.20.114/32 -all
  • _iwdxd3znjvbpor9oxrt7ueu97pre0d3
  • atlassian-domain-verification=wBrOFASBvgMlndoPMoLnMXMQ0t0IIHBccg5cHWmjXhAG9EC6iB9ECCaYRauSjrH8
  • apple-domain-verification=nZJtwjBRd3g62bv7
  • wombat-verification=3KwxVCQV1HEp-aRXRTKKaZ5G0frhk
  • vmware-cloud-verification-3f13823e-3431-4b3f-946c-497a80925af0
  • mongodb-site-verification=tGHKhQ3sT7vJGNoofFBzim544ND2MBuC
  • duo_sso_verification=fE7QwooS3gEzoDaYrAw6CDGiMPeAsTJGDsaBgh54a1xpvf0hetU6n6UlZ74dmGXc
  • anthropic-domain-verification-fs80sa=IjQ2HQhdWeSlodlsu18tG17FS
  • _2rq3fokmjopqkzp97lazj8o73inhc5h
Cloud / SaaS Services Detected
Apple Atlassian Box Anthropic JamF Zoho Campaigns Cisco Cisco Duo ServiceNow

Leak Screenshot:

Leak Screenshot