# LockBit lists Indian firm via FortiBleed flaw

Published: 2026-08-03 · Severity: medium · Sectors: manufacturing
Canonical: https://vorant.io/reports/5f57151e-0d3e-5ccb-8eee-874d3e339cce/lockbit-lists-indian-firm-via-fortibleed-flaw

> LockBit ransomware operators posted an Indian company as a victim, noting stolen FortiOS SSL-VPN credentials tied to the FortiBleed flaw.

Ransomware.live's tracker has added pcclimitedindia.com to LockBit's leak site listing. The associated data notes that credentials for the victim's FortiOS SSL-VPN were exposed through the previously disclosed "FortiBleed" vulnerability (CVE-2022-40684), suggesting this exposure may have contributed to initial access or lateral movement in the intrusion.

The listing includes minimal detail beyond compromised-employee counts and DNS records for the victim domain, consistent with a standard extortion posting rather than a full breach report. No stolen data samples or additional infrastructure details were disclosed in the source material.

This appears to be a routine addition to LockBit's ongoing victim disclosure operations rather than a novel technique or large-scale campaign, though the FortiBleed credential exposure underscores the continued risk of unpatched or previously-exploited Fortinet SSL-VPN appliances being leveraged by ransomware affiliates.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)
- Threat actors: LockBit
- Malware: LockBit

Source reporting: https://www.ransomware.live/id/cGNjbGltaXRlZGluZGlhLmNvbUBsb2NrYml0NQ==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5f57151e-0d3e-5ccb-8eee-874d3e339cce/lockbit-lists-indian-firm-via-fortibleed-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
