# INC Ransom claims Gamaus via FortiBleed flaw

Published: 2026-08-12 · Severity: elevated
Canonical: https://vorant.io/reports/b76bd2ad-3fb1-5950-a88c-98807e59ce2d/inc-ransom-claims-gamaus-via-fortibleed-flaw

> The INC Ransom gang added gamaus.com to its leak site after exposed FortiOS SSL-VPN creds via the FortiBleed bug (CVE-2022-40684).

Ransomware.live's tracker logged a new victim, gamaus.com, on the INC Ransom extortion site. The listing notes the target's FortiOS SSL-VPN credentials were previously exposed through the 2022 'FortiBleed' authentication-bypass vulnerability (CVE-2022-40684), suggesting the exposed VPN credentials may have provided the initial access vector used by the intrusion, though the source does not explicitly confirm the exploitation chain.

The entry reports a small externally-visible attack surface (4 assets) and 13 compromised user accounts, with no employee or third-party credential exposure noted. No stolen data samples, ransom note, or additional technical detail beyond the leak-site metadata are provided, limiting confidence in root-cause attribution to the FortiBleed flaw versus other access methods.

This is a routine ransomware-leak-site listing rather than a novel campaign; INC Ransom continues to add victims that had known, unpatched Fortinet SSL-VPN exposure, reinforcing the ongoing risk that unremediated CVE-2022-40684 deployments pose as a foothold for ransomware affiliates.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)
- Threat actors: INC Ransom
- Malware: INC Ransom

Source reporting: https://www.ransomware.live/id/Z2FtYXVzLmNvbUBpbmNyYW5zb20=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b76bd2ad-3fb1-5950-a88c-98807e59ce2d/inc-ransom-claims-gamaus-via-fortibleed-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
