1. Executive summary
On 2026-09-10, the ransomware group "clop" listed Harley-Davidson (harley-davidson[.]com, US) as a victim on its leak site. No technical detail on the intrusion itself is available in the source material — no CVE, no malware sample, no exfiltration evidence — and the listing is a claim by the operator, not a corroborated breach. Attribution to "clop" is unconfirmed: the actor has no MITRE ATT&CK profile in our verified reference data, and the listing is single-sourced from ransomware[.]live. Contextual exposure data for the victim domain (FortiOS SSL-VPN credentials exposed via the "FortiBleed" leak, CVE-2022-40684) is suggestive of a possible initial-access route but is not evidence of the access vector actually used here. Bottom line for EMEA financial services: no direct operational impact, but any client with Harley-Davidson as a counterparty, supplier, or brand partner should treat third-party exposure as plausible until disproven.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The item is an uncorroborated leak-site listing against a US non-financial entity; there is no confirmed incident, no EU/UK-impacted entity identified, and no fact distinctive enough to trigger an article from the regulatory reference. Clients should re-assess if corroboration emerges or if a third-party relationship to the victim is confirmed.
3. Technical analysis & attack chain
No confirmed attack chain can be reconstructed from the source material. The listing contains only: group (clop), victim (harley-davidson[.]com), country (US), and publication timestamp (2026-09-10T10:22:04Z). Ransomware[.]live explicitly does not access or verify underlying stolen data, so the listing is an operator claim.
What the source does provide is victim-side exposure context, which is not evidence of the intrusion path:
- FortiOS SSL-VPN credential exposure. The victim domain's FortiOS SSL-VPN credentials were exposed via the "FortiBleed" leak (CVE-2022-40684). CVE-2022-40684 is a known authentication-bypass on Fortinet FortiOS/FortiProxy management interfaces; harvested credentials from this leak are a plausible initial-access commodity for any actor, including ransomware operators. The verified reference data provides no CVSS, severity, or CISA-KEV state for this CVE in the context of this item, so we do not assess it here.
- Infostealer-attributed credential exposure. Hudson Rock-sourced context on the listing page reports 18 compromised employees, 2,828 compromised users, 38 third-party employee credentials, and an external attack surface of 105 assets for the victim domain. These figures describe infostealer infections among the victim's workforce and user base — a recognised precursor pattern to ransomware via initial-access brokers — but the source does not assert these infections were used in this incident.
Confidence caveat: every substantive claim in this section is single-sourced (ransomware[.]live / Hudson Rock context block). There is no second source confirming the breach, the actor, the access vector, or any data theft. Treat as unverified until corroborated; do not act on it as an established fact.
4. Mitigation & containment
No victim-side containment applies to clients directly. Actions are third-party-risk-driven:
P1 — within 24h
- Identify any relationship to Harley-Davidson within your third-party inventory: dealer finance arrangements, fleet/leasing, corporate cards, loyalty or co-brand programmes, marketing/brand partnerships, or supply of parts/services. If a relationship exists, open a supplier incident query under your third-party incident process.
- Search your environment for harley-davidson[.]com and related dealer-domain indicators in proxy, DNS, and email logs to rule out any unexpected interaction.
P2 — within 72h
- For any confirmed third-party relationship, request written confirmation from the counterparty on breach status and any data shared with your organisation (employee PII, payment data, contract terms).
- Review whether any of your staff credentials appear in infostealer-derived exposure relating to counterparties; enforce password reset and MFA re-enrolment where matched.
P3 — within 7 days
- Fold the outcome into your third-party risk reviews: if the counterparty confirms compromise, reassess their risk rating and any concentration exposure.
- Separately, and independent of this item: if your estate includes FortiOS/FortiProxy SSL-VPN, verify you are patched against CVE-2022-40684, rotate all admin and SSL-VPN credentials, and confirm management interfaces are not internet-facing. The FortiBleed credential leak is a standing commodity for initial-access actors.
5. Indicators of compromise
No indicators of compromise available in the source material. The listing provides no hashes, malware artefacts, infrastructure, or exfiltrated-data samples. The victim domain harley-davidson[.]com is a legitimate corporate domain and is not an IOC.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live — "Victim: HARLEY-DAVIDSON.COM – clop" — https://www.ransomware.live/id/SEFSTEVZLURBVklEU09OLkNPTUBjbG9w — 2026-09-10 (listing timestamp 10:22 UTC; page includes Hudson Rock-sourced exposure context and FortiBleed/CVE-2022-40684 credential-exposure note)
8. Adverse Trace position
This is a low-confidence, single-sourced leak-site listing with no corroborating technical detail — we assess it as an unconfirmed claim, not an established breach, and the "clop" attribution is unconfirmed (no MITRE ATT&CK profile in our verified reference data). Severity for EMEA financial services clients is low absent a confirmed third-party relationship; the actionable value is procedural, not technical: inventory your exposure to the named victim, and use the FortiBleed context as a prompt to verify your own Fortinet SSL-VPN posture. We will monitor for corroboration — a victim statement, a second telemetry source, or sample data — and will reissue this advisory at version 2.0 with an updated regulatory assessment if the incident is confirmed or an EU/UK nexus emerges.
Published via PulseTrace — Adverse Trace threat intelligence.