Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Sunlight Express Airways

sunlightair.ph

Group Payload
Discovered 2026-04-16 12:25 UTC
Est. attack date 2026-04-16
Country PH
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Sunlight Air offers affordable flights to popular Philippine island destinations such as Cebu, Coron, Boracay, Siquijor, and Siargao. The airline provides various services including private charters, vacation packages, and a loyalty program called Sunlight Miles. Targeting both leisure and business travelers, Sunlight Air aims to enhance the travel experience with exclusive passenger perks and flexible booking options. With a commitment to expanding flight frequencies and routes, the company continues to facilitate convenient travel across the Philippines.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 30

Third Party Employee Credentials: 1


External Attack Surface: 9


FortiBleed Exposure Detected

This domain's FortiOS SSL-VPN credentials were exposed via the "FortiBleed" leak (CVE-2022-40684).


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • sunlightair-ph.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=Ollq3F2uDj_xIrmb0PmpZeICOlasQWvJ3ahsLUSUby0
  • MS=ms65927860
  • v=spf1 include:spf.protection.outlook.com include:amazonses.com -all
  • sunlightairph.azurewebsites.net
  • google-site-verification=fkvMzntOBrYPkrHxfDljHw96q9uuSa06OKx79d6fYsM
Cloud / SaaS Services Detected
Amazon SES/WorkMail Microsoft 365

Leak Screenshot:

Leak Screenshot