~/f4n6 $ grep -r "Ransomware: lockbit5 named fdcputman.nl (NL)" ./investigations/ --include="*.md"

Ransomware: lockbit5 named fdcputman.nl (NL)

Jeff Davies 08 Sep 2026 6 min read

1. Executive summary

On 2026-09-08, the ransomware operator branding itself "lockbit5" listed the Dutch financial services firm FDC Putman (fdcputman.nl) as a victim on its leak site. FDC Putman is a financial specialist offering advice on mortgages, insurance, and related products — a profile that implies processing of client financial and personal data. The listing claims data theft and extortion; no technical detail on initial access, malware, or exfiltration volume is present in the source material, and the "lockbit5" designation carries no MITRE ATT&CK profile in our verified reference data — attribution to any established LockBit operation is unconfirmed. The same actor has recently listed at least three other Benelux/German victims (fpmanagement.nl, a licensed Dutch trust office; takt.be, a Belgian notary firm; probat.com, a German industrial group), indicating an active campaign targeting NL/BE/DE businesses, including regulated financial-sector entities. No CISA-KEV exploitation state, CVSS score, or vulnerability data is associated with this item — it is a leak-site listing, not a CVE.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 19: reporting of major ICT-related incidents to competent authorities A Dutch financial-sector advisory firm (mortgage/insurance advice) has been publicly listed as a ransomware victim with claimed data theft — if FDC Putman is an in-scope financial entity, this is a potential major ICT-related incident with a published extortion claim. In-scope clients with a comparable exposure (extortion listing naming the firm) must assess against their Art. 19 major-incident thresholds and be prepared to file within the prescribed timelines; a leak-site listing alone is an unverified claim, but the classification exercise under Art. 18 is triggered.
DORA Art. 18: classification of ICT-related incidents and cyber threats The listing is a cyber threat event affecting an identified NL financial-services firm, with a claimed (unverified) data breach. Clients must run this through their incident classification process to determine severity/criticality before deciding on reporting — the public extortion claim is the classification input, not proof of compromise.

No NIS2 or UK NIS article is directly engaged by this item: the victim is a Dutch financial advisory firm, and nothing in the source material indicates an essential/important entity under NIS2 Art. 23 or an OES/RDSP under UK NIS 2018. We note the related victim fpmanagement.nl is a licensed trust office — if that sector linkage were confirmed for a client's own third parties, NIS2 Art. 21(2)(d) supply chain security measures could become relevant, but that is not established by this item.

3. Technical analysis & attack chain

What is confirmed (from the source material)

  1. The actor operating under the name "lockbit5" published a victim entry for fdcputman.nl on its leak site, dated 2026-09-08.
  2. The listing includes a leak screenshot and DNS records for the victim domain, per the ransomware.live mirror — consistent with standard leak-site practice of claiming exfiltrated data as extortion leverage.
  3. FDC Putman is a Dutch financial specialist (mortgages, insurance, and related advisory).
  4. The same actor has listed at least three other victims in the same period: fpmanagement.nl (NL, licensed trust office, Rotterdam), takt.be (BE, notary services), probat.com (DE, industrial group, Emmerich am Rhein).

What is NOT in the source material — treat as unknown

  • Initial access vector, exploited vulnerability or CVE, malware family, payload, persistence mechanism, C2 infrastructure, lateral movement, exfiltration method, and encryption behaviour. None are described.
  • Whether data was actually exfiltrated. The leak-site listing is a claim by the extortionist; ransomware.live explicitly does not host or verify the underlying stolen data.
  • Any connection between "lockbit5" and the historical LockBit operation (LockBit 3.0 / Bitwise Spider / LockBitSupp). The name may be a rebrand, a successor, or an unrelated actor trading on the brand. The verified reference data contains no MITRE ATT&CK profile for "lockbit5" — attribution is unconfirmed.

Single-source caveat: All victim and campaign detail in this advisory derives from ransomware.live's indexing of the lockbit5 leak site — a single source. No independent corroboration (victim statement, CERT-NL advisory, law-enforcement confirmation) is present in the provided material. Verify before enforcement: treat the listing as an extortion claim, not a confirmed intrusion, until FDC Putman or Dutch authorities (NCSC-NL / DNB) confirm.

Assessment of the campaign pattern: The victim set — a mortgage/insurance adviser, a licensed trust office, and a notary — is consistent with targeting of professional-services firms holding high-value financial and identity data. For EMEA financial services clients, the relevant exposure is third-party: advisers, trust offices, and notaries frequently hold or process client financial data on behalf of banks, insurers, and asset managers.

4. Mitigation & containment

This is a third-party exposure item, not a vulnerability with a patch path. Actions are directed at clients' exposure to the named victim and the actor's campaign pattern.

P1 — within 24h

  • If FDC Putman (or fpmanagement.nl, takt.be, probat.com) is a known third party, counterparty, or introducer: identify what data, credentials, or system access the relationship involves. Suspend non-essential data sharing with the affected party pending their confirmation of compromise status.
  • Hunt your environment for the affected domains (fdcputman[.]nl, fpmanagement.nl, takt.be, probat.com) in proxy, DNS, and email logs over the past 90 days — look for inbound attachments, credential sharing, or outbound traffic that could indicate pre-incident interaction.
  • Check whether any of your staff or clients have used FDC Putman advisory services; client-side data (mortgage applications, identity documents, financial statements) may be in the claimed exfil set.

P2 — within 72h

  • If a data-sharing or API connection exists with any listed victim, rotate all shared credentials, API keys, and integration tokens as a precaution.
  • Review third-party risk register entries for NL/BE/DE professional-services providers in the financial chain (advisers, trust offices, notaries) and confirm their incident-notification obligations contractually — see DORA Art. 30: key contractual provisions with ICT third-party providers.
  • Brief fraud/AML teams: if identity or financial documentation from the claimed breach surfaces, expect attempted account takeover or fraud against affected individuals.

P3 — within 7 days

  • Monitor the lockbit5 leak site and ransomware.live for additional listings in your sector or supply chain; the actor is actively posting NL/BE/DE victims.
  • If you operate in the Dutch financial sector, review your own Art. 18 classification process against the scenario "our firm appears on a leak site" — the first external signal of a major incident is often the extortion listing itself, not an internal alert.

5. Indicators of compromise

No indicators of compromise available in the source material. The leak-site listing contains no malware hashes, C2 domains, IP addresses, or other atomic indicators. The victim domains listed below are victim infrastructure, not attacker infrastructure — do not block them; use them for log review as directed in §4.

type value confidence source
domain (victim) fdcputman[.]nl High — victim identity confirmed by listing ransomware.live
domain (victim) fpmanagement[.]nl High — separate listing, same actor ransomware.live
domain (victim) takt[.]be High — separate listing, same actor ransomware.live
domain (victim) probat[.]com High — separate listing, same actor ransomware.live
domain  fdcputman[.]nl
domain  fpmanagement[.]nl
domain  takt[.]be
domain  probat[.]com

Note: These are victim domains for threat-hunting pivots (log review, third-party mapping), not malicious indicators. No attacker-side IOCs exist in the source material.

6. Detection

Insufficient indicators to author detection rules. The source material contains no malware artefacts, strings, command-line indicators, or behavioural telemetry. The only observable is the leak-site listing itself, which is not a detection artefact.

7. Sources

  • Ransomware.live — Ransomware: lockbit5 named fdcputman.nl (NL) — https://www.ransomware.live/id/ZmRjcHV0bWFuLm5sQGxvY2tiaXQ1 — 2026-09-08
  • Ransomware.live — Ransomware: lockbit5 named fpmanagement.nl (NL) — https://www.ransomware.live/id/ZnBtYW5hZ2VtZW50Lm5sQGxvY2tiaXQ1 — accessed 2026-09-08
  • Ransomware.live — Ransomware: lockbit5 named takt.be (BE) — https://www.ransomware.live/id/dGFrdC5iZUBsb2NrYml0NQ== — accessed 2026-09-08
  • Ransomware.live — Ransomware: lockbit5 named probat.com (DE) — https://www.ransomware.live/id/cHJvYmF0LmNvbUBsb2NrYml0NQ== — accessed 2026-09-08

8. Adverse Trace position

This is a leak-site extortion listing against a Dutch financial advisory firm by an actor with no confirmed MITRE ATT&CK profile — attribution to the historical LockBit operation is unconfirmed and the "lockbit5" name should not be treated as evidence of lineage. Severity for direct client impact is moderate: no client systems are implicated, no technical detail exists to act on, and the listing is single-sourced and unverified. The material risk is third-party — the actor is demonstrably targeting NL/BE/DE financial-chain professional services (adviser, trust office, notary), which is exactly the vendor and introducer population EMEA financial institutions depend on. Clients should run the P1 third-party exposure check now, and compliance teams should note that a leak-site listing is itself a classification trigger under DORA Art. 18 and potentially a reporting trigger under Art. 19 if the victim is in scope. Adverse Trace will monitor for: (a) confirmation or denial from FDC Putman or Dutch authorities, (b) additional lockbit5 listings in the financial sector, and (c) any technical detail or IOC set emerging from follow-on reporting. We will reissue if corroboration or attacker-side indicators appear.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies