> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Ransomware: lockbit5 named fdcputman.nl (NL)
- URL: https://f4n6.co.uk/security-feed/ransomware-lockbit5-named-fdcputman-nl-nl/
- Published: 2026-09-08T20:21:33.000Z
- Updated: 2026-09-08T20:21:33.000Z
- Author: Jeff Davies
- Tags: #security-feed, lockbit5

## 1\. Executive summary

On 2026-09-08, the ransomware operator branding itself "lockbit5" listed the Dutch financial services firm FDC Putman (fdcputman.nl) as a victim on its leak site. FDC Putman is a financial specialist offering advice on mortgages, insurance, and related products — a profile that implies processing of client financial and personal data. The listing claims data theft and extortion; no technical detail on initial access, malware, or exfiltration volume is present in the source material, and the "lockbit5" designation carries no MITRE ATT&CK profile in our verified reference data — attribution to any established LockBit operation is **unconfirmed**. The same actor has recently listed at least three other Benelux/German victims (fpmanagement.nl, a licensed Dutch trust office; takt.be, a Belgian notary firm; probat.com, a German industrial group), indicating an active campaign targeting NL/BE/DE businesses, including regulated financial-sector entities. No CISA-KEV exploitation state, CVSS score, or vulnerability data is associated with this item — it is a leak-site listing, not a CVE.

## 2\. Regulatory framing

| Article                                                                         | Trigger (the fact in this item)                                                                                                                                                                                                                                              | Practical impact                                                                                                                                                                                                                                                                                                   |
| ------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | A Dutch financial-sector advisory firm (mortgage/insurance advice) has been publicly listed as a ransomware victim with claimed data theft — if FDC Putman is an in-scope financial entity, this is a potential major ICT-related incident with a published extortion claim. | In-scope clients with a comparable exposure (extortion listing naming the firm) must assess against their Art. 19 major-incident thresholds and be prepared to file within the prescribed timelines; a leak-site listing alone is an unverified claim, but the classification exercise under Art. 18 is triggered. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats         | The listing is a cyber threat event affecting an identified NL financial-services firm, with a claimed (unverified) data breach.                                                                                                                                             | Clients must run this through their incident classification process to determine severity/criticality before deciding on reporting — the public extortion claim is the classification input, not proof of compromise.                                                                                              |

No NIS2 or UK NIS article is directly engaged by this item: the victim is a Dutch financial advisory firm, and nothing in the source material indicates an essential/important entity under NIS2 Art. 23 or an OES/RDSP under UK NIS 2018\. We note the related victim fpmanagement.nl is a licensed trust office — if that sector linkage were confirmed for a client's own third parties, NIS2 Art. 21(2)(d) supply chain security measures could become relevant, but that is not established by this item.

## 3\. Technical analysis & attack chain

### What is confirmed (from the source material)

1. The actor operating under the name "lockbit5" published a victim entry for fdcputman.nl on its leak site, dated 2026-09-08.
2. The listing includes a leak screenshot and DNS records for the victim domain, per the ransomware.live mirror — consistent with standard leak-site practice of claiming exfiltrated data as extortion leverage.
3. FDC Putman is a Dutch financial specialist (mortgages, insurance, and related advisory).
4. The same actor has listed at least three other victims in the same period: fpmanagement.nl (NL, licensed trust office, Rotterdam), takt.be (BE, notary services), probat.com (DE, industrial group, Emmerich am Rhein).

### What is NOT in the source material — treat as unknown

- Initial access vector, exploited vulnerability or CVE, malware family, payload, persistence mechanism, C2 infrastructure, lateral movement, exfiltration method, and encryption behaviour. None are described.
- Whether data was actually exfiltrated. The leak-site listing is a claim by the extortionist; ransomware.live explicitly does not host or verify the underlying stolen data.
- Any connection between "lockbit5" and the historical LockBit operation (LockBit 3.0 / Bitwise Spider / LockBitSupp). The name may be a rebrand, a successor, or an unrelated actor trading on the brand. **The verified reference data contains no MITRE ATT&CK profile for "lockbit5" — attribution is unconfirmed.**

**Single-source caveat:** All victim and campaign detail in this advisory derives from ransomware.live's indexing of the lockbit5 leak site — a single source. No independent corroboration (victim statement, CERT-NL advisory, law-enforcement confirmation) is present in the provided material. Verify before enforcement: treat the listing as an extortion claim, not a confirmed intrusion, until FDC Putman or Dutch authorities (NCSC-NL / DNB) confirm.

**Assessment of the campaign pattern:** The victim set — a mortgage/insurance adviser, a licensed trust office, and a notary — is consistent with targeting of professional-services firms holding high-value financial and identity data. For EMEA financial services clients, the relevant exposure is third-party: advisers, trust offices, and notaries frequently hold or process client financial data on behalf of banks, insurers, and asset managers.

## 4\. Mitigation & containment

This is a third-party exposure item, not a vulnerability with a patch path. Actions are directed at clients' exposure to the named victim and the actor's campaign pattern.

### P1 — within 24h

- If FDC Putman (or fpmanagement.nl, takt.be, probat.com) is a known third party, counterparty, or introducer: identify what data, credentials, or system access the relationship involves. Suspend non-essential data sharing with the affected party pending their confirmation of compromise status.
- Hunt your environment for the affected domains (fdcputman\[.\]nl, fpmanagement.nl, takt.be, probat.com) in proxy, DNS, and email logs over the past 90 days — look for inbound attachments, credential sharing, or outbound traffic that could indicate pre-incident interaction.
- Check whether any of your staff or clients have used FDC Putman advisory services; client-side data (mortgage applications, identity documents, financial statements) may be in the claimed exfil set.

### P2 — within 72h

- If a data-sharing or API connection exists with any listed victim, rotate all shared credentials, API keys, and integration tokens as a precaution.
- Review third-party risk register entries for NL/BE/DE professional-services providers in the financial chain (advisers, trust offices, notaries) and confirm their incident-notification obligations contractually — see DORA Art. 30: key contractual provisions with ICT third-party providers.
- Brief fraud/AML teams: if identity or financial documentation from the claimed breach surfaces, expect attempted account takeover or fraud against affected individuals.

### P3 — within 7 days

- Monitor the lockbit5 leak site and ransomware.live for additional listings in your sector or supply chain; the actor is actively posting NL/BE/DE victims.
- If you operate in the Dutch financial sector, review your own Art. 18 classification process against the scenario "our firm appears on a leak site" — the first external signal of a major incident is often the extortion listing itself, not an internal alert.

## 5\. Indicators of compromise

No indicators of compromise available in the source material. The leak-site listing contains no malware hashes, C2 domains, IP addresses, or other atomic indicators. The victim domains listed below are **victim infrastructure, not attacker infrastructure** — do not block them; use them for log review as directed in §4.

| type            | value               | confidence                                  | source          |
| --------------- | ------------------- | ------------------------------------------- | --------------- |
| domain (victim) | fdcputman\[.\]nl    | High — victim identity confirmed by listing | ransomware.live |
| domain (victim) | fpmanagement\[.\]nl | High — separate listing, same actor         | ransomware.live |
| domain (victim) | takt\[.\]be         | High — separate listing, same actor         | ransomware.live |
| domain (victim) | probat\[.\]com      | High — separate listing, same actor         | ransomware.live |

```iocs
domain  fdcputman[.]nl
domain  fpmanagement[.]nl
domain  takt[.]be
domain  probat[.]com

```

**Note:** These are victim domains for threat-hunting pivots (log review, third-party mapping), not malicious indicators. No attacker-side IOCs exist in the source material.

## 6\. Detection

Insufficient indicators to author detection rules. The source material contains no malware artefacts, strings, command-line indicators, or behavioural telemetry. The only observable is the leak-site listing itself, which is not a detection artefact.

## 7\. Sources

- Ransomware.live — *Ransomware: lockbit5 named fdcputman.nl (NL)* — https://www.ransomware.live/id/ZmRjcHV0bWFuLm5sQGxvY2tiaXQ1 — 2026-09-08
- Ransomware.live — *Ransomware: lockbit5 named fpmanagement.nl (NL)* — https://www.ransomware.live/id/ZnBtYW5hZ2VtZW50Lm5sQGxvY2tiaXQ1 — accessed 2026-09-08
- Ransomware.live — *Ransomware: lockbit5 named takt.be (BE)* — https://www.ransomware.live/id/dGFrdC5iZUBsb2NrYml0NQ== — accessed 2026-09-08
- Ransomware.live — *Ransomware: lockbit5 named probat.com (DE)* — https://www.ransomware.live/id/cHJvYmF0LmNvbUBsb2NrYml0NQ== — accessed 2026-09-08

## 8\. Adverse Trace position

This is a leak-site extortion listing against a Dutch financial advisory firm by an actor with **no confirmed MITRE ATT&CK profile** — attribution to the historical LockBit operation is unconfirmed and the "lockbit5" name should not be treated as evidence of lineage. Severity for direct client impact is **moderate**: no client systems are implicated, no technical detail exists to act on, and the listing is single-sourced and unverified. The material risk is third-party — the actor is demonstrably targeting NL/BE/DE financial-chain professional services (adviser, trust office, notary), which is exactly the vendor and introducer population EMEA financial institutions depend on. Clients should run the P1 third-party exposure check now, and compliance teams should note that a leak-site listing is itself a classification trigger under DORA Art. 18 and potentially a reporting trigger under Art. 19 if the victim is in scope. Adverse Trace will monitor for: (a) confirmation or denial from FDC Putman or Dutch authorities, (b) additional lockbit5 listings in the financial sector, and (c) any technical detail or IOC set emerging from follow-on reporting. We will reissue if corroboration or attacker-side indicators appear.

---

[Read the original source →](https://www.ransomware.live/id/ZmRjcHV0bWFuLm5sQGxvY2tiaXQ1?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*