Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2026-04-20 20:36 UTC
Est. attack date 2026-04-20
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Rheem Manufacturing Company 1100 Abernathy Road, Suite 1700 Atlanta, GA 30328, United States www.rheem.com is a well-established manufacturer specializing in heating, cooling, and water heating products. Founded in 1925, the company has its headquarters in Atlanta, Georgia, and has grown to become a global leader in its industry. Company Overview. Rheem produces a wide range of products, including residential and commercial water heaters, boilers, air conditioning units, and heating, ventilation, and air conditioning (HVAC) equipment. The company is particularly noted for its commitment to energy efficiency, offering numerous ENERGY STAR® certified products. Leaked data: 320 GB (479,856 Files, 76,897 Folders) includes developments: technical documentation, drawings, test reports and other technical information, employee data containing personal information, corporate information, contracts and agreements (including non-disclosure agreements), financial information and metrics, and much more.

Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 100

Third Party Employee Credentials: 29


External Attack Surface: 41


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaintsmarkmonitor.com
  • whoisrequestmarkmonitor.com
MX Records
  • rheem-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • teamviewer-sso-verification=2635a35c920d4972a227f0cccd7629f3
  • v=spf1 ip4:63.76.193.37 ip4:63.76.193.12 ip4:66.231.88.207 ip4:66.231.89.168 ip4:107.23.16.222 ip4:54.173.83.138 ip4:208.85.50.148 ip4:35.80.141.6 ip4:44.229.121.55 ip4:54.205.217.180 ip4:20.119.163.56 ip4:148.59.100.16/28" " include:_spf.psm.knowbe4.com include:servers.mcsv.net include:spf.ipzmarketing.com include:spf_c.oraclecloud.com include:spf.icontroller.eu include:spf.protection.outlook.com include:_spf.e2ma.net include:rp.oracleemaildelivery.com -all
  • adobe-sign-verification=d6c2ed0df422a001eaaf5de9729aba4e
  • atlassian-domain-verification=Lrl4cX3kM3FF4NhW4wIQAZXbGwZxv4GOeoH2UdAs6G/1A9mKkztBogwJ7hQJVXsI
  • dropbox-domain-verification=fgeb444uulxq
  • google-site-verification=Lbbz0Kz5WrQ54aUYmpHJrCbV-CxpU4LZ1oGrBD194hs
Cloud / SaaS Services Detected
Atlassian Dropbox Mailchimp Box Teamviewer Oracle Cloud KnowBe4

Leak Screenshot:

Leak Screenshot