> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Ransomware: clop named HARLEY-DAVIDSON.COM (US)
- URL: https://f4n6.co.uk/security-feed/ransomware-clop-named-harley-davidson-com-us/
- Published: 2026-09-10T15:42:45.000Z
- Updated: 2026-09-10T15:42:45.000Z
- Author: Jeff Davies
- Tags: #security-feed, Clop

## 1\. Executive summary

On 2026-09-10, the ransomware group "clop" listed Harley-Davidson (harley-davidson\[.\]com, US) as a victim on its leak site. No technical detail on the intrusion itself is available in the source material — no CVE, no malware sample, no exfiltration evidence — and the listing is a claim by the operator, not a corroborated breach. Attribution to "clop" is **unconfirmed**: the actor has no MITRE ATT&CK profile in our verified reference data, and the listing is single-sourced from ransomware\[.\]live. Contextual exposure data for the victim domain (FortiOS SSL-VPN credentials exposed via the "FortiBleed" leak, CVE-2022-40684) is suggestive of a possible initial-access route but is **not** evidence of the access vector actually used here. Bottom line for EMEA financial services: no direct operational impact, but any client with Harley-Davidson as a counterparty, supplier, or brand partner should treat third-party exposure as plausible until disproven.

## 2\. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The item is an uncorroborated leak-site listing against a US non-financial entity; there is no confirmed incident, no EU/UK-impacted entity identified, and no fact distinctive enough to trigger an article from the regulatory reference. Clients should re-assess if corroboration emerges or if a third-party relationship to the victim is confirmed.

## 3\. Technical analysis & attack chain

No confirmed attack chain can be reconstructed from the source material. The listing contains only: group (clop), victim (harley-davidson\[.\]com), country (US), and publication timestamp (2026-09-10T10:22:04Z). Ransomware\[.\]live explicitly does not access or verify underlying stolen data, so the listing is an operator claim.

What the source does provide is victim-side exposure context, which is **not** evidence of the intrusion path:

1. **FortiOS SSL-VPN credential exposure.** The victim domain's FortiOS SSL-VPN credentials were exposed via the "FortiBleed" leak (CVE-2022-40684). CVE-2022-40684 is a known authentication-bypass on Fortinet FortiOS/FortiProxy management interfaces; harvested credentials from this leak are a plausible initial-access commodity for any actor, including ransomware operators. The verified reference data provides no CVSS, severity, or CISA-KEV state for this CVE in the context of this item, so we do not assess it here.
2. **Infostealer-attributed credential exposure.** Hudson Rock-sourced context on the listing page reports 18 compromised employees, 2,828 compromised users, 38 third-party employee credentials, and an external attack surface of 105 assets for the victim domain. These figures describe infostealer infections among the victim's workforce and user base — a recognised precursor pattern to ransomware via initial-access brokers — but the source does not assert these infections were used in this incident.

**Confidence caveat:** every substantive claim in this section is single-sourced (ransomware\[.\]live / Hudson Rock context block). There is no second source confirming the breach, the actor, the access vector, or any data theft. Treat as unverified until corroborated; do not act on it as an established fact.

## 4\. Mitigation & containment

No victim-side containment applies to clients directly. Actions are third-party-risk-driven:

### P1 — within 24h

- Identify any relationship to Harley-Davidson within your third-party inventory: dealer finance arrangements, fleet/leasing, corporate cards, loyalty or co-brand programmes, marketing/brand partnerships, or supply of parts/services. If a relationship exists, open a supplier incident query under your third-party incident process.
- Search your environment for harley-davidson\[.\]com and related dealer-domain indicators in proxy, DNS, and email logs to rule out any unexpected interaction.

### P2 — within 72h

- For any confirmed third-party relationship, request written confirmation from the counterparty on breach status and any data shared with your organisation (employee PII, payment data, contract terms).
- Review whether any of your staff credentials appear in infostealer-derived exposure relating to counterparties; enforce password reset and MFA re-enrolment where matched.

### P3 — within 7 days

- Fold the outcome into your third-party risk reviews: if the counterparty confirms compromise, reassess their risk rating and any concentration exposure.
- Separately, and independent of this item: if your estate includes FortiOS/FortiProxy SSL-VPN, verify you are patched against CVE-2022-40684, rotate all admin and SSL-VPN credentials, and confirm management interfaces are not internet-facing. The FortiBleed credential leak is a standing commodity for initial-access actors.

## 5\. Indicators of compromise

No indicators of compromise available in the source material. The listing provides no hashes, malware artefacts, infrastructure, or exfiltrated-data samples. The victim domain harley-davidson\[.\]com is a legitimate corporate domain and is **not** an IOC.

## 6\. Detection

Insufficient indicators to author detection rules.

## 7\. Sources

- Ransomware.live — "Victim: HARLEY-DAVIDSON.COM – clop" — https://www.ransomware.live/id/SEFSTEVZLURBVklEU09OLkNPTUBjbG9w — 2026-09-10 (listing timestamp 10:22 UTC; page includes Hudson Rock-sourced exposure context and FortiBleed/CVE-2022-40684 credential-exposure note)

## 8\. Adverse Trace position

This is a **low-confidence, single-sourced leak-site listing with no corroborating technical detail** — we assess it as an unconfirmed claim, not an established breach, and the "clop" attribution is unconfirmed (no MITRE ATT&CK profile in our verified reference data). Severity for EMEA financial services clients is low absent a confirmed third-party relationship; the actionable value is procedural, not technical: inventory your exposure to the named victim, and use the FortiBleed context as a prompt to verify your own Fortinet SSL-VPN posture. We will monitor for corroboration — a victim statement, a second telemetry source, or sample data — and will reissue this advisory at version 2.0 with an updated regulatory assessment if the incident is confirmed or an EU/UK nexus emerges.

---

[Read the original source →](https://www.ransomware.live/id/SEFSTEVZLURBVklEU09OLkNPTUBjbG9w?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*