Ransomware.Live Ransomhouse Targets Pertamina in Latest Ransomware Attack
Article Content
- •Pertamina is the latest victim of Ransomhouse, linked to the FortiBleed vulnerability.
- •CVE-2022-40684 has been actively exploited since October 2022.
- •Organizations are urged to patch FortiOS vulnerabilities to prevent similar attacks.
Ransomhouse has claimed a new victim, Pertamina, following the exposure of FortiOS SSL-VPN credentials due to the 'FortiBleed' vulnerability (CVE-2022-40684). This vulnerability was publicly disclosed on October 18, 2022, and has been actively exploited since October 11, 2022. The attack has led to the publication of DNS records associated with Pertamina, indicating a significant breach. The incident follows a similar attack on the City of Fort Smith, Arkansas, which also involved the same CVE. Both attacks highlight the ongoing threat posed by ransomware groups exploiting known vulnerabilities. As of now, the extent of data exfiltration or operational disruption at Pertamina remains unclear. The situation emphasizes the need for organizations to patch vulnerabilities promptly and monitor their systems for unusual activity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track RansomHouse, City Of Fort Smith Arkansas and CVE-2022-40684 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Japan Faces Record Ransomware Attacks in H1 2026 In the first half of 2026, Japan recorded a staggering 123 ransomware attacks, the highest since data collection began in 2020. The National Police Agency (NPA) reported an average of 13,687 suspicious access attempts per IP address daily, marking a significant increase from the previous year. Small and medium-sized…
Ransomware Attacks Target Education and Defense Sectors On September 16, 2026, Odyssey Charter School, Inc. was listed as a victim on the WALLSTREET ransomware group's leak site, marking a potential ransomware attack. The listing lacks details on whether data was encrypted or exfiltrated. Similarly, on the same day, ARDA, a public-sector organization in the government and…