~/f4n6 $ grep -r "Ransomware: clop named HARLEY-DAVIDSON.COM (US)" ./investigations/ --include="*.md"

Ransomware: clop named HARLEY-DAVIDSON.COM (US)

Jeff Davies 10 Sep 2026 3 min read

1. Executive summary

On 2026-09-10, the ransomware group "clop" listed Harley-Davidson (harley-davidson[.]com, US) as a victim on its leak site. No technical detail on the intrusion itself is available in the source material — no CVE, no malware sample, no exfiltration evidence — and the listing is a claim by the operator, not a corroborated breach. Attribution to "clop" is unconfirmed: the actor has no MITRE ATT&CK profile in our verified reference data, and the listing is single-sourced from ransomware[.]live. Contextual exposure data for the victim domain (FortiOS SSL-VPN credentials exposed via the "FortiBleed" leak, CVE-2022-40684) is suggestive of a possible initial-access route but is not evidence of the access vector actually used here. Bottom line for EMEA financial services: no direct operational impact, but any client with Harley-Davidson as a counterparty, supplier, or brand partner should treat third-party exposure as plausible until disproven.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The item is an uncorroborated leak-site listing against a US non-financial entity; there is no confirmed incident, no EU/UK-impacted entity identified, and no fact distinctive enough to trigger an article from the regulatory reference. Clients should re-assess if corroboration emerges or if a third-party relationship to the victim is confirmed.

3. Technical analysis & attack chain

No confirmed attack chain can be reconstructed from the source material. The listing contains only: group (clop), victim (harley-davidson[.]com), country (US), and publication timestamp (2026-09-10T10:22:04Z). Ransomware[.]live explicitly does not access or verify underlying stolen data, so the listing is an operator claim.

What the source does provide is victim-side exposure context, which is not evidence of the intrusion path:

  1. FortiOS SSL-VPN credential exposure. The victim domain's FortiOS SSL-VPN credentials were exposed via the "FortiBleed" leak (CVE-2022-40684). CVE-2022-40684 is a known authentication-bypass on Fortinet FortiOS/FortiProxy management interfaces; harvested credentials from this leak are a plausible initial-access commodity for any actor, including ransomware operators. The verified reference data provides no CVSS, severity, or CISA-KEV state for this CVE in the context of this item, so we do not assess it here.
  2. Infostealer-attributed credential exposure. Hudson Rock-sourced context on the listing page reports 18 compromised employees, 2,828 compromised users, 38 third-party employee credentials, and an external attack surface of 105 assets for the victim domain. These figures describe infostealer infections among the victim's workforce and user base — a recognised precursor pattern to ransomware via initial-access brokers — but the source does not assert these infections were used in this incident.

Confidence caveat: every substantive claim in this section is single-sourced (ransomware[.]live / Hudson Rock context block). There is no second source confirming the breach, the actor, the access vector, or any data theft. Treat as unverified until corroborated; do not act on it as an established fact.

4. Mitigation & containment

No victim-side containment applies to clients directly. Actions are third-party-risk-driven:

P1 — within 24h

  • Identify any relationship to Harley-Davidson within your third-party inventory: dealer finance arrangements, fleet/leasing, corporate cards, loyalty or co-brand programmes, marketing/brand partnerships, or supply of parts/services. If a relationship exists, open a supplier incident query under your third-party incident process.
  • Search your environment for harley-davidson[.]com and related dealer-domain indicators in proxy, DNS, and email logs to rule out any unexpected interaction.

P2 — within 72h

  • For any confirmed third-party relationship, request written confirmation from the counterparty on breach status and any data shared with your organisation (employee PII, payment data, contract terms).
  • Review whether any of your staff credentials appear in infostealer-derived exposure relating to counterparties; enforce password reset and MFA re-enrolment where matched.

P3 — within 7 days

  • Fold the outcome into your third-party risk reviews: if the counterparty confirms compromise, reassess their risk rating and any concentration exposure.
  • Separately, and independent of this item: if your estate includes FortiOS/FortiProxy SSL-VPN, verify you are patched against CVE-2022-40684, rotate all admin and SSL-VPN credentials, and confirm management interfaces are not internet-facing. The FortiBleed credential leak is a standing commodity for initial-access actors.

5. Indicators of compromise

No indicators of compromise available in the source material. The listing provides no hashes, malware artefacts, infrastructure, or exfiltrated-data samples. The victim domain harley-davidson[.]com is a legitimate corporate domain and is not an IOC.

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live — "Victim: HARLEY-DAVIDSON.COM – clop" — https://www.ransomware.live/id/SEFSTEVZLURBVklEU09OLkNPTUBjbG9w — 2026-09-10 (listing timestamp 10:22 UTC; page includes Hudson Rock-sourced exposure context and FortiBleed/CVE-2022-40684 credential-exposure note)

8. Adverse Trace position

This is a low-confidence, single-sourced leak-site listing with no corroborating technical detail — we assess it as an unconfirmed claim, not an established breach, and the "clop" attribution is unconfirmed (no MITRE ATT&CK profile in our verified reference data). Severity for EMEA financial services clients is low absent a confirmed third-party relationship; the actionable value is procedural, not technical: inventory your exposure to the named victim, and use the FortiBleed context as a prompt to verify your own Fortinet SSL-VPN posture. We will monitor for corroboration — a victim statement, a second telemetry source, or sample data — and will reissue this advisory at version 2.0 with an updated regulatory assessment if the incident is confirmed or an EU/UK nexus emerges.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies