Ransomware Victim: Law Offices US immigrationonline.com (Triple X)

Fecha
13 Jun 2026
Actor
triple-x
Tipo
Ransomware
Pais
United States
Sector
Banking
Confianza
high
60
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

2IOCs
0TTPs
triple-xActor
United StatesPais
Executive Summary
Victima de ransomware reportada en el dashboard de Triple X.

Key Points

  • Ransomware Dashboard
  • Fuente original

Law Offices US immigrationonline.com

Victima de ransomware reportada en el dashboard de Triple X.

CampoValor
GrupoTriple X
PaisUS
SectorBusiness Services
Fecha2026-06-13T10:07:27.122967+00:00

Detalles

https://immigrationonline.com/ 1.5 terabytes of people's data in a immigrationonline law firm. Server overload and lack of updates have caused important data to be exposed to potential leaks. At the same time, many of these financial and tax documents also contain sensitive personal information, including full names, home addresses, Social Security numbers, banking details, and contact information. what will leak ? Confidential court cases : Details of lawsuits, complaints, or defenses that have not yet been filed in court. Financial and banking information : Sensitive client accounts, contracts, or transactions. Intellectual property documents : Such as patents, designs, or business contracts that have not yet been made public. Private correspondence and emails : Communications between the attorney and the client that should remain strictly confidential. what data will leak ? 24,900 passport files sample Tax forms of employees and colleagues sample ID cards and driver’s licenses sample few sample pics: pic 1 pic 2 pic 3 pic 4 pic 5 This is probably the right moment to point out that, at a certain stage, virtually any data breach is still a reversible situation. Companies are usually given an opportunity to contain the damage and resolve the issue albeit at a price. But despite knowing exactly what was happening, and fully understanding that it was putting the security and privacy of its own employees at risk, the company made a calculated decision to let it happen. And now the company will tell its employees: “Sorry, we’ve experienced a data breach, and your passports are now publicly available online.” But they will never say: “We were offered a chance to pay to prevent your passports from being published, but we decided it wasn’t worth it so now they’re on the internet. Sorry.” download data link : http://6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad.onion/immigrationonline.com/

Referencias

Diamond Model

Adversary
triple-x
Ver perfil →
Victim
Ransomware Victim: Law Offices US immigrationonline.com (Triple X)
United States
Capability
Ransomware
Infrastructure
immigrationonline.com
6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad.onion

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain immigrationonline.com Extraido del contenido VT OffSec SOCRadar
Domain 6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad.onion Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor triple-x en el blog → Ver triple-x en IntelTracker → URL IntelTracker: 6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad.onion → Fuente OSINT: 6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad.onion → Buscar triple-x en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes