Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Traverse City Area Public Schools

tcaps.net

Group Medusa
Discovered 2024-04-14 13:08 UTC
Est. attack date 2024-04-13
Country US

Description:

Traverse City Area Public Schools is a public school district based in Traverse City, Michigan, United States. This district includes 10 elementary schools, 2 middle schools, 2 high schools, 1 alternative high school, and 1 Montessori school. The district serves 8,908 students. Traverse City Area Public Schools school district office is located in 412 Webster St Rm C, Traverse City, Michigan, 49686, United States and has 932 employees. The total amount of data leakage is 1.2 TB

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 75

Third Party Employee Credentials: 2


External Attack Surface: 19


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registrar-abusecloudflare.com
MX Records
  • alt1.aspmx.l.google.com. Google Workspace
  • alt2.aspmx.l.google.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
  • alt3.aspmx.l.google.com. Google Workspace
  • alt4.aspmx.l.google.com. Google Workspace
TXT Records
  • v=msv1 t=BDCC343B-3841-4109-9351-F6C92E3D9F95
  • v=spf1 include:spf_target.brightarrow.com include:_spf.google.com include:sendgrid.net ip4:136.228.36.130/26 ip4:64.88.122.227 ~all
  • vgcpsq6t528nd29pqmahiruril
  • adobe-idp-site-verification=ecfe4e67f6a514effe5238c0cd1f4d8e11f7dbfa3c5fb94c3104370721400245
  • apple-domain-verification=55FoHosbv9B4f8qx
  • asv=d224c4be5a77355fa9de072bab8bf9c6
  • cisco-ci-domain-verification=1e6b988f653a64e240a6ae222421c1689e7f9eebd2f81615ffc21bc9c8034baa
  • duo_sso_verification=5j8zVRNPQZhbVwOvyslEH7NaudnB76rZXbLgxnBwAXDb0m8TgG3JQa2eCsH108qG
  • kg6icb2oc5f9geo6io1vj3sn3d
  • ptu86atbsso0onfoodoqm34i0r
Cloud / SaaS Services Detected
Adobe Apple Cisco SendGrid Cisco Duo

Leak Screenshot:

Leak Screenshot