VORANT. Threat Intelligence Research Sign in Create a free account

Gentlemen ransomware hits Saskatoon Tribal Council

high threat government-national

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Ransomware group "TheGentlemen" claims Saskatoon Tribal Council as a victim, linked to exposed FortiOS SSL-VPN credentials from a 2022 FortiBleed leak.

Ransomware.live tracked a listing from the ransomware group known as "TheGentlemen" naming the Saskatoon Tribal Council, a Canadian Indigenous governance organization, as a victim. The entry notes that the victim's domain had FortiOS SSL-VPN credentials exposed via the so-called "FortiBleed" leak, tied to CVE-2022-40684, an authentication bypass vulnerability in FortiOS/FortiProxy that has been actively exploited since 2022 to harvest credentials and gain unauthorized access to SSL-VPN appliances.

No additional technical details, ransom note content, exfiltrated data samples, or infrastructure indicators are provided in this listing beyond the victim naming and the vulnerability reference. The entry appears to be a standard leak-site tracking record rather than original incident analysis, and it is sponsored content referencing Hudson Rock's infostealer intelligence tooling.

Defenders operating Fortinet SSL-VPN appliances should verify patch status against CVE-2022-40684, rotate any credentials that may have been exposed through this or related FortiOS vulnerabilities, and review VPN authentication logs for anomalous access patterns. Organizations should also monitor ransomware leak sites for their own exposure and treat credential-harvesting from edge devices as a precursor to ransomware deployment.

Mentioned in this report

Vulnerabilities CVE-2022-40684KEV
Threat actors The Gentlemen
Malware Gentlemen

Detection guidance

1 detections for this report are in the app — rules that match its indicators, converted to Splunk SPL, Microsoft KQL and Elastic, plus YARA and Suricata. Three days of it free, no card.

Source reporting: https://www.ransomware.live/id/U2Fza2F0b29uIFRyaWJhbCBDb3VuY2lsQHRoZWdlbnRsZW1lbg==

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,183 reports from 148 sources, 503 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs