Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Tricolor Holdings

tricolor.com

Discovered 2026-02-25 05:44 UTC
Est. attack date 2026-02-25
Country US

Description:

Mission-driven auto lender expanding access to affordable vehicle ownership nationwide. Deadline: 2026-03-03T00:00:00+00:00 Status: Awaiting Contact

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 41

Third Party Employee Credentials: 14


External Attack Surface: 6


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registrar-abusecloudflare.com
MX Records
  • tricolor-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=9N_7IgEU3rVtF5WuKqR1FOtw4wreFY5g-CE0U6t3kB8
  • google-site-verification=BhQ6GHN7VA3RIGYsbHjlEmhKtP7amAjaPAiIDG4iO2M
  • nb7seaihapvas01d9n4ej8gjqd
  • umjo3r987okic6fb34mj4tjh3r
  • v=spf1 include:spf.protection.outlook.com include:spf.emailsignatures365.com include:spf_c.oraclecloud.com -all
  • webapplication-tricolor-release.azurewebsites.net
  • 3q269eb565hk2h2jh3gucgug8s
  • 6OkTG2eRJJgjuFiCfyODXB68z8DKyC7Ysf71Et5Z33JgW5Ky8eI/hNjehKFJV9DEnJe9xOBsgn0ppHadf0a5Hg
  • 6OkTG2eRJJgjuFiCfyODXB68z8DKyC7Ysf71Et5Z33JgW5Ky8eI/hNjehKFJV9DEnJe9xOBsgn0ppHadf0a5Hg==
  • G/WfymIaK6CRqLGDxBRktFy9w0yuHEwRdgHyEyJzMgs=
  • apple-domain-verification=2ytX01GM7242aUyD
  • apple-domain-verification=I2zKDMRrj2If6zTd
Cloud / SaaS Services Detected
Apple Oracle Cloud

Leak Screenshot:

Leak Screenshot