# Krybit leaks ProHealth Singapore VPN creds

Published: 2026-08-02 · Severity: medium · Sectors: healthcare
Canonical: https://vorant.io/reports/1e6d3716-793c-5f6a-9d23-82c586dd69d4/krybit-leaks-prohealth-singapore-vpn-creds

> Ransomware group Krybit exposed FortiOS SSL-VPN credentials for Singapore's ProHealth, tied to the 2022 FortiBleed flaw (CVE-2022-40684).

Ransomware.live has indexed a leak entry attributed to the Krybit ransomware operation, listing prohealth.sg (ProHealth Singapore) as a victim. The listing states that the organization's FortiOS SSL-VPN credentials were exposed via the FortiBleed vulnerability, an authentication bypass in Fortinet's FortiOS/FortiProxy administrative interface that was disclosed in 2022 and has been widely abused by multiple threat actors to harvest VPN credentials and gain initial network access.

The entry appears to be a standard victim-shaming leak post rather than a detailed technical disclosure, providing DNS records and a screenshot as proof of compromise. No malware samples, additional infrastructure, or a full description of the intrusion chain following credential theft were provided in the source material. Given the healthcare sector nexus and use of a known, patchable Fortinet vulnerability for initial access, this represents a routine but concerning case of unpatched edge infrastructure being leveraged for ransomware operations.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)
- Threat actors: Krybit

Source reporting: https://www.ransomware.live/id/d3d3LnByb2hlYWx0aC5zZ0BrcnliaXQ=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1e6d3716-793c-5f6a-9d23-82c586dd69d4/krybit-leaks-prohealth-singapore-vpn-creds.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
