Direwolf ransomware lists ION Xperiences as victim
Ransomware.live shows Direwolf ransomware group listed ION Xperiences as a victim, citing exposed FortiOS SSL-VPN credentials from the 2022 FortiBleed flaw.
A victim entry on ransomware.live attributes a compromise of the organization identified as ION Xperiences to the Direwolf ransomware operation. The listing, sourced from Hudson Rock cybercrime intelligence tooling, reports a modest exposure footprint: no directly compromised employees, 44 compromised user accounts, 113 third-party employee credential exposures, and 11 external attack surface findings. Notably, the entry states that the victim's FortiOS SSL-VPN credentials were exposed via the FortiBleed vulnerability (CVE-2022-40684), a known path-traversal flaw that allows unauthenticated attackers to read arbitrary files, including admin credentials, from Fortinet FortiOS/FortiProxy devices.
The posting provides no additional technical detail beyond DNS records and a leak screenshot, and does not describe the intrusion chain, ransomware payload behavior, or data exfiltrated. Defenders operating FortiOS SSL-VPN appliances should treat any unpatched CVE-2022-40684 exposure as a credential-theft risk and rotate VPN credentials, enforce MFA, and confirm patch levels, since infostealer-harvested or leak-derived credentials are a recurring precursor to ransomware deployment as highlighted by the Hudson Rock sponsorship note.
This is a routine victim-disclosure listing rather than a novel campaign report; there is no indication of a large-scale or targeted operation beyond the single named victim.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/aVNPTiBYUEVSSUVOQ0VTQGRpcmV3b2xm
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free