# TheGentlemen ransomware claims Auren victim

Published: 2026-09-30 · Severity: high
Canonical: https://vorant.io/reports/9a518e44-5a32-5cef-9fd9-ea3ae8e769b0/thegentlemen-ransomware-claims-auren-victim

> Ransomware group 'thegentlemen' lists Auren as a victim, citing exposed FortiOS SSL-VPN credentials tied to the FortiBleed flaw.

Ransomware.live tracked a victim listing for Auren attributed to a ransomware operation known as 'thegentlemen'. The entry, sourced from a leak-site tracker, reports compromise indicators including 3 compromised employees, 30 compromised users, 20 third-party employee credential exposures, and 10 external attack surface findings for the victim's domain.

Notably, the listing states that FortiOS SSL-VPN credentials belonging to the victim's domain were exposed via the 'FortiBleed' leak, associated with CVE-2022-40684 (a Fortinet FortiOS/FortiProxy authentication bypass vulnerability). This suggests initial access or credential exposure may be linked to unpatched or previously compromised Fortinet VPN appliances. Defenders operating FortiOS/FortiProxy devices should verify patch status against CVE-2022-40684, rotate SSL-VPN credentials, and review logs for anomalous authentication events, especially where credentials may have been previously harvested via infostealer infections as referenced in the source's sponsor content.

No further technical detail, ransomware encryption specifics, or TTPs are provided in this listing. This appears to be a leak-site tracking entry rather than a full incident report; defenders in industries connected to Auren or using similar Fortinet infrastructure should prioritize credential rotation and exposure checks.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)
- Threat actors: The Gentlemen
- Malware: Gentlemen

1 more detection for this report is in the app: the rules that match its indicators, every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. A new account gets three days of them free.

Source reporting: https://www.ransomware.live/id/QXVyZW5AdGhlZ2VudGxlbWVu

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9a518e44-5a32-5cef-9fd9-ea3ae8e769b0/thegentlemen-ransomware-claims-auren-victim.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
