# Gentlemen ransomware hits Saskatoon Tribal Council

Published: 2026-10-09 · Severity: high · Sectors: government-national
Canonical: https://vorant.io/reports/5ad78afd-4465-5b52-aacd-d5389fb56c23/gentlemen-ransomware-hits-saskatoon-tribal-council

> Ransomware group "TheGentlemen" claims Saskatoon Tribal Council as a victim, linked to exposed FortiOS SSL-VPN credentials from a 2022 FortiBleed leak.

Ransomware.live tracked a listing from the ransomware group known as "TheGentlemen" naming the Saskatoon Tribal Council, a Canadian Indigenous governance organization, as a victim. The entry notes that the victim's domain had FortiOS SSL-VPN credentials exposed via the so-called "FortiBleed" leak, tied to CVE-2022-40684, an authentication bypass vulnerability in FortiOS/FortiProxy that has been actively exploited since 2022 to harvest credentials and gain unauthorized access to SSL-VPN appliances.

No additional technical details, ransom note content, exfiltrated data samples, or infrastructure indicators are provided in this listing beyond the victim naming and the vulnerability reference. The entry appears to be a standard leak-site tracking record rather than original incident analysis, and it is sponsored content referencing Hudson Rock's infostealer intelligence tooling.

Defenders operating Fortinet SSL-VPN appliances should verify patch status against CVE-2022-40684, rotate any credentials that may have been exposed through this or related FortiOS vulnerabilities, and review VPN authentication logs for anomalous access patterns. Organizations should also monitor ransomware leak sites for their own exposure and treat credential-harvesting from edge devices as a precursor to ransomware deployment.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)
- Threat actors: The Gentlemen
- Malware: Gentlemen

1 more detection for this report is in the app: the rules that match its indicators, every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. A new account gets three days of them free.

Source reporting: https://www.ransomware.live/id/U2Fza2F0b29uIFRyaWJhbCBDb3VuY2lsQHRoZWdlbnRsZW1lbg==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5ad78afd-4465-5b52-aacd-d5389fb56c23/gentlemen-ransomware-hits-saskatoon-tribal-council.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
