LockBit lists Indian firm via FortiBleed flaw
LockBit ransomware operators posted an Indian company as a victim, noting stolen FortiOS SSL-VPN credentials tied to the FortiBleed flaw.
Ransomware.live's tracker has added pcclimitedindia.com to LockBit's leak site listing. The associated data notes that credentials for the victim's FortiOS SSL-VPN were exposed through the previously disclosed "FortiBleed" vulnerability (CVE-2022-40684), suggesting this exposure may have contributed to initial access or lateral movement in the intrusion.
The listing includes minimal detail beyond compromised-employee counts and DNS records for the victim domain, consistent with a standard extortion posting rather than a full breach report. No stolen data samples or additional infrastructure details were disclosed in the source material.
This appears to be a routine addition to LockBit's ongoing victim disclosure operations rather than a novel technique or large-scale campaign, though the FortiBleed credential exposure underscores the continued risk of unpatched or previously-exploited Fortinet SSL-VPN appliances being leveraged by ransomware affiliates.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/cGNjbGltaXRlZGluZGlhLmNvbUBsb2NrYml0NQ==
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free