~/f4n6 $ grep -r "Ransomware: lockbit5 named hygear.com (DE)" ./investigations/ --include="*.md"

Ransomware: lockbit5 named hygear.com (DE)

Jeff Davies 19 Sep 2026 4 min read

1. Executive summary

On 18 September 2026 the ransomware operator using the name "lockbit5" listed hygear.com, a German hydrogen and industrial services provider, as a victim on its leak site. The listing is a claim of compromise and probable data theft; no technical detail on intrusion method, malware, or encryption status is published. Attribution to the LockBit brand is unconfirmed: the actor "lockbit5" has no MITRE ATT&CK profile in our verified reference data, and rebranding under defunct ransomware names is common. The single corroborating detail beyond the claim itself is that hygear.com's FortiOS SSL-VPN credentials were exposed via the "FortiBleed" leak (CVE-2022-40684), which is a plausible initial-access route but is not confirmed as the vector for this incident.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The item is a third-party claim of compromise against a German industrial services firm; no fact in the source establishes that a client of Adverse Trace is impacted, that stolen data includes client data, or that an incident has occurred within a regulated entity's own ICT environment. Clients with a direct supplier relationship to hygear.com should treat this as a third-party risk signal under their existing ICT third-party risk processes rather than as a triggering incident.

3. Technical analysis & attack chain

The source material is a leak-site listing plus victim metadata. There is no confirmed attack chain: no intrusion telemetry, no malware samples, no post-exploitation detail, and no confirmation that encryption or exfiltration occurred. The listing itself is the only primary artefact.

What the source does establish:

  1. The actor "lockbit5" published a victim entry for hygear.com, country Germany, on or before 18 September 2026.
  2. The victim operates in hydrogen and industrial services ("reliable and affordable on-site and on-demand hydrogen and industrial" services, per the truncated listing description).
  3. Ransomware.live's enrichment for the domain states that hygear.com's FortiOS SSL-VPN credentials were exposed via the "FortiBleed" leak, which corresponds to CVE-2022-40684, an authentication bypass on Fortinet FortiOS and FortiProxy administrative interfaces.

The FortiBleed credential exposure is the only technically actionable element. CVE-2022-40684 allowed an unauthenticated attacker to add their own SSH key or API token to an admin account on a FortiOS/FortiProxy device, and mass exploitation in October 2022 produced credential and configuration leaks at scale. If hygear.com's SSL-VPN portal was compromised through that leak, the exposed credentials could have provided initial access to the internal network at any point after the original exposure. This is a plausible route, not a confirmed one: the source does not link the credential leak to the lockbit5 intrusion, and credentials exposed in 2022 may have been rotated since.

Single-sourced and unconfirmed claims: the entire incident rests on the lockbit5 leak-site claim as indexed by Ransomware.live. No second source corroborates the compromise, the data volume, or the intrusion method. The "lockbit5" name implies affiliation with the LockBit operation disrupted by Operation Cronos in February 2024, but no MITRE ATT&CK profile exists for this actor in our verified reference data and the affiliation is unconfirmed; the original LockBit's source code and brand have circulated among multiple successor groups.

4. Mitigation & containment

This section is written for Adverse Trace clients, not for the victim. There are no victim-side IOCs to act on.

P1 (within 24h):

  • Identify whether hygear.com appears in your vendor master, supply chain, or third-party payment records. If a relationship exists, contact the supplier through a known-good channel to establish whether your data, credentials, or contractual information was held on their systems.
  • If your organisation has any inbound access from hygear.com (partner VPN, file exchange, API integration), suspend it until the supplier confirms its environment is clean.

P2 (within 72h):

  • Review authentication logs for the past 30 days for any accounts or service principals associated with hygear.com integrations, looking for anomalous logins or privilege changes.
  • If shared credentials exist for the integration, rotate them regardless of the supplier's response.

P3 (within 7 days):

  • For clients running FortiOS or FortiProxy SSL-VPN: verify that devices are patched against CVE-2022-40684 and that no unauthorised SSH keys or API tokens exist on admin accounts. The FortiBleed exposure shows this vulnerability's credential leaks remain a live initial-access commodity years after disclosure.
  • Record the hygear.com relationship status and any actions taken in your ICT third-party risk register, so the outcome feeds supplier reassessment rather than sitting in a ticket.

5. Indicators of compromise

No indicators of compromise available in the source material. The listing provides no hashes, file names, infrastructure, or victim-side artefacts. The only domain in the source, hygear.com, is the victim's legitimate domain and is not an indicator.

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live, "Victim: hygear.com – lockbit5", https://www.ransomware.live/id/aHlnZWFyLmNvbUBsb2NrYml0NQ==, 18 September 2026
  • Ransomware.live victim enrichment (FortiBleed/FortiOS SSL-VPN credential exposure note, DNS records), https://www.ransomware.live/id/aHlnZWFyLmNvbUBsb2NrYml0NQ==, accessed 19 September 2026

8. Adverse Trace position

We assess this item as low-to-medium relevance for EMEA financial services clients: it is a single-sourced leak-site claim against a German industrial supplier, with unconfirmed attribution to the LockBit brand and no technical detail to act on. The claim should not be treated as a confirmed breach, and enforcement actions against the supplier should wait for corroboration. The one transferable lesson is the FortiBleed credential exposure: unpatched FortiOS SSL-VPN portals from the 2022 exploitation window remain a viable initial-access route into supplier networks, and clients should confirm their own and their critical suppliers' Fortinet estate is patched and audited for rogue admin keys. We will monitor for a second source corroborating the hygear.com compromise, for sample or infrastructure releases tied to lockbit5, and for any indication that client data is present in a future leak.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies