Skip to main content
Meridian Energy
Request a Demo

Finding CF-3040

Critical exposure on vpn.meridianenergy.example

Mark in progressFalse positive
Back to findings
CriticalIn progress
EmployeeDetected 2026-07-13 22:47Seen 2× across sources

Credential evidence

Passwords are masked — full values require reveal permission
Login URL
https://vpn.meridianenergy.example/remote
Password
Qt8••••••••
Matched asset
vpn.meridianenergy.example
First seen in log
2026-07-13

Infected device

Device
LAPTOP-V3M8Q6
Operating system
Windows 11 Home 23H2
IP at capture
198.51.100.27
Country
Türkiye
Infected at
2026-07-13 09:13
Antivirus
Not detected in log

Source block

Block
BLK-88031
Stealer family
Lumma
Posted
2026-07-13 03:41
Channel
Underground forum listing
Lines in block
773

Related findings

Triage timeline

  1. 2026-07-13 22:47 · System

    Finding created from stealer block and matched to asset vpn.meridianenergy.example

  2. 2026-07-13 22:47 · System

    Severity set to Critical based on asset criticality and credential context

  3. 2026-07-13 09:30 · A. Analyst

    Status changed to In progress

  4. Awaiting next analyst action