VORANT. Threat Intelligence Research Sign in Create a free account

IncRansom claims BCX South Africa breach

severe threat technologytelecommunications

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Ransomware group IncRansom lists South African IT firm BCX as a victim, with exposure linked to a leaked FortiOS SSL-VPN credential flaw.

Ransomware.live's leak-site tracker recorded a new victim posting by the IncRansom ransomware group naming bcx.co.za (BCX, a South African IT services and telecommunications provider) as a victim. The listing cites compromised employee and third-party credentials (152 employees, 61 users, 268 third-party credentials) and an external attack surface of 89 assets, alongside DNS records for the victim domain.

Notably, the entry states that the victim's FortiOS SSL-VPN credentials were exposed via the historic "FortiBleed" vulnerability (CVE-2022-40684), an authentication-bypass flaw in FortiOS/FortiProxy that has been exploited in numerous ransomware intrusions since 2022. This suggests the initial access vector may be tied to unpatched or previously-exploited Fortinet infrastructure rather than a novel technique. No malware samples, hashes, or network IOCs were published in this listing; it functions as a leak-site claim rather than a technical analysis.

Defenders using Fortinet SSL-VPN products should verify patch status against CVE-2022-40684, rotate any credentials that may have been exposed historically via this flaw, and review VPN authentication logs for anomalous access. Organizations related to or doing business with BCX should monitor for potential downstream exposure of shared or third-party credentials referenced in the listing.

Mentioned in this report

Vulnerabilities CVE-2022-40684KEV
Threat actors INC Ransom
Malware INC Ransom

Source reporting: https://www.ransomware.live/id/YmN4LmNvLnphQGluY3JhbnNvbQ==

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,316 reports from 152 sources, 2,734 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs