# Direwolf ransomware lists ION Xperiences as victim

Published: 2026-08-21 · Severity: high
Canonical: https://vorant.io/reports/4744afb8-23a4-55ff-a18e-7747d27bf790/direwolf-ransomware-lists-ion-xperiences-as-victim

> Ransomware.live shows Direwolf ransomware group listed ION Xperiences as a victim, citing exposed FortiOS SSL-VPN credentials from the 2022 FortiBleed flaw.

A victim entry on ransomware.live attributes a compromise of the organization identified as ION Xperiences to the Direwolf ransomware operation. The listing, sourced from Hudson Rock cybercrime intelligence tooling, reports a modest exposure footprint: no directly compromised employees, 44 compromised user accounts, 113 third-party employee credential exposures, and 11 external attack surface findings. Notably, the entry states that the victim's FortiOS SSL-VPN credentials were exposed via the FortiBleed vulnerability (CVE-2022-40684), a known path-traversal flaw that allows unauthenticated attackers to read arbitrary files, including admin credentials, from Fortinet FortiOS/FortiProxy devices.

The posting provides no additional technical detail beyond DNS records and a leak screenshot, and does not describe the intrusion chain, ransomware payload behavior, or data exfiltrated. Defenders operating FortiOS SSL-VPN appliances should treat any unpatched CVE-2022-40684 exposure as a credential-theft risk and rotate VPN credentials, enforce MFA, and confirm patch levels, since infostealer-harvested or leak-derived credentials are a recurring precursor to ransomware deployment as highlighted by the Hudson Rock sponsorship note.

This is a routine victim-disclosure listing rather than a novel campaign report; there is no indication of a large-scale or targeted operation beyond the single named victim.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)
- Threat actors: Dire Wolf
- Malware: Direwolf

Source reporting: https://www.ransomware.live/id/aVNPTiBYUEVSSUVOQ0VTQGRpcmV3b2xm

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4744afb8-23a4-55ff-a18e-7747d27bf790/direwolf-ransomware-lists-ion-xperiences-as-victim.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
