# Qilin ransomware hits Island via FortiBleed flaw

Published: 2026-09-27 · Severity: high
Canonical: https://vorant.io/reports/8ef1fcc7-ba2f-5fc0-aa64-b421389001f9/qilin-ransomware-hits-island-via-fortibleed-flaw

> Qilin ransomware group listed victim 'Island' after exploiting FortiOS SSL-VPN credential leak flaw CVE-2022-40684 (FortiBleed).

Ransomware.live's tracker recorded a new victim, identified only as 'Island', added to the Qilin ransomware group's leak site. According to the entry, the victim's FortiOS SSL-VPN credentials were exposed through the previously disclosed 'FortiBleed' vulnerability (CVE-2022-40684), an authentication bypass affecting Fortinet FortiOS and FortiProxy SSL-VPN and administrative interfaces that allows an unauthenticated attacker to retrieve credentials and other sensitive data.

The listing is consistent with the pattern of Qilin and other ransomware affiliates opportunistically scanning for and exploiting unpatched Fortinet appliances to obtain initial access via stolen VPN credentials, then pivoting to internal compromise and data exfiltration/extortion. No additional technical detail, IOCs, or sector information was provided in this record beyond the CVE reference and DNS records for the victim domain.

Defenders using FortiOS/FortiProxy SSL-VPN should verify they are patched against CVE-2022-40684, rotate any credentials that may have been exposed via vulnerable devices, and review SSL-VPN and firewall logs for anomalous authentication activity, particularly from unrecognized IPs, as a precursor to ransomware deployment.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)
- Threat actors: qilin
- Malware: Qilin

Source reporting: https://www.ransomware.live/id/SXNsYW5kQHFpbGlu

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8ef1fcc7-ba2f-5fc0-aa64-b421389001f9/qilin-ransomware-hits-island-via-fortibleed-flaw.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
