VORANT. Threat Intelligence Sign in Get the full feed

LockBit lists Indian firm via FortiBleed flaw

medium threat manufacturing

LockBit ransomware operators posted an Indian company as a victim, noting stolen FortiOS SSL-VPN credentials tied to the FortiBleed flaw.

Ransomware.live's tracker has added pcclimitedindia.com to LockBit's leak site listing. The associated data notes that credentials for the victim's FortiOS SSL-VPN were exposed through the previously disclosed "FortiBleed" vulnerability (CVE-2022-40684), suggesting this exposure may have contributed to initial access or lateral movement in the intrusion.

The listing includes minimal detail beyond compromised-employee counts and DNS records for the victim domain, consistent with a standard extortion posting rather than a full breach report. No stolen data samples or additional infrastructure details were disclosed in the source material.

This appears to be a routine addition to LockBit's ongoing victim disclosure operations rather than a novel technique or large-scale campaign, though the FortiBleed credential exposure underscores the continued risk of unpatched or previously-exploited Fortinet SSL-VPN appliances being leveraged by ransomware affiliates.

Mentioned in this report

Vulnerabilities CVE-2022-40684KEV
Threat actors LockBit
Malware LockBit

Source reporting: https://www.ransomware.live/id/cGNjbGltaXRlZGluZGlhLmNvbUBsb2NrYml0NQ==

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free