FortiRecon Dark Web Field Guide: What's Actually Out There

Satyam Maurya Published 22 Apr 2026  ·  By Satyam Maurya  ·  Threat Mitigation  ·  26 min read

The 2026 "dark web" is not a single hidden place. It is an economy — a fluid network of infostealer log drops, ransomware leak sites, criminal Telegram channels and the smoking remains of BreachForums / Genesis / XSS / RAMP. This is a field guide to what is actually out there, what FortiRecon sees across its Adversary-Centric Intelligence module, and what it means for an Indian enterprise in 2026.

Every load-bearing claim below is sourced from a CISA #StopRansomware advisory, a DOJ / NCA / Europol press release, a named vendor threat-research paper, or a CERT-In advisory. URLs are inline. No marketing claims, no invented percentages, no "industry estimates."

🧠 Credential records

100 billion+

On darknet (Fortinet 2025 GTLR)

📈 Infostealer surge

500% / 42%

YoY log activity / credential surge

💸 Akira proceeds

$244.17M

CISA AA24-109A, late Sep 2025

📡 Telegram scale

43.5M channels

Blocked by Telegram in 2025

🇮🇳 India context

16B credentials

CERT-In CIAD-2025-0018

Disclosure: Ogma Consulting is an authorised Fortinet partner and operates FortiRecon as a managed service for Indian enterprises. This is a technical field guide built on public law-enforcement and vendor research. Where an industry claim cannot be traced to a primary source, we flag it in-line.


Part 1 — The Infostealer Log Economy

The single largest source of new credentials on the dark web in 2026 is not a breached database. It is the daily output of infostealer malware running on compromised consumer PCs — crypto wallets, corporate SSO cookies, VPN credentials, session tokens. Every day, tens of thousands of fresh "logs" hit markets, Telegram channels and private brokers.

394,000

Windows PCs infected by Lumma Stealer in just 60 days — between 16 March and 16 May 2025, per Microsoft Threat Intelligence. Microsoft's Digital Crimes Unit filed a civil legal action on 13 May 2025; law enforcement seized or transferred 1,300+ domains of Lumma's infrastructure, with another 300 actioned by Europol.

Source: Microsoft — "Disrupting Lumma Stealer" (21 May 2025)

Lumma is a malware-as-a-service. Its primary developer operates under the handle "Shamel", based in Russia. Pricing tiers are public: Experienced $250, Professional $500, Corporate $1,000, Source $20,000. In a November 2023 interview Shamel claimed about 400 active clients. Microsoft's action did not shut Lumma down — Check Point Research showed on 29 May 2025 that log-sale activity on Russian Market had climbed from 95 post-takedown to 406 within days.

Lumma / LummaC2

Infostealer MaaS Disrupted, not dead
Targets
Chromium / Mozilla browser credentials + cookies, crypto wallets (MetaMask, Electrum, Exodus), VPN configs, email/FTP clients, Telegram Desktop tdata, documents.
Delivery
ClickFix campaigns ("paste this into Run to verify"), malvertising, cracked software, hijacked YouTube tutorials, GitHub/MediaFire payloads.
Impact
Microsoft DCU tracked 394,000 infections in 60 days (Mar–May 2025). Check Point India data: 44,000+ Indian Windows systems hit in the same window.

RedLine + META

Infostealer MaaS Seized Oct 2024
Price
$100–$150 one-time (threat-actor forum listings, per FortiGuard); ESET observed $150/month or $900 lifetime for panel access.
Scale
ESET identified over 1,000 unique IP addresses hosting RedLine panels (Nov 2022 – Mar 2023). Operation Magnus on 28 October 2024 disrupted both RedLine and META (Dutch Police + FBI + Eurojust).
Status
Post-takedown, the brands survive primarily through repackaged and legacy builds. ESET confirmed that the same developer authored both RedLine and META.

Vidar 2.0

Infostealer Active 2025
Release
Developer "Loadbaks" announced Vidar 2.0 on 6 October 2025, priced at US$300.
Upgrade
Complete rewrite from C++ to C, multithreaded, RC4 encryption, polymorphic builder. Bypasses Chromium AppBound encryption by launching the browser with debugging enabled and pulling keys from memory (Trend Micro, Oct 2025).
Timing
The release coincides with a decline in Lumma activity — classic displacement effect after Microsoft's May 2025 action.

Raccoon / Mark Sokolovsky

Infostealer Prosecuted
Model
Lease $200/month, cryptocurrency only. Stole login credentials, financial information, personal records from victims globally.
Arrest
Sokolovsky (Ukraine) arrested by Dutch authorities in March 2022. Extradited to US February 2024. Pleaded guilty; 60-month federal sentence; $910,844.61 restitution; $23,975 forfeiture (US DOJ / USAO-WDTX).

StealC (and SHAMOS on macOS)

Infostealer Cross-platform shift
StealC
Emerged January 2023 as a self-described copycat of Vidar, Raccoon, Mars and RedLine. V2 released in March 2025 with RC4 encryption and a streamlined C2 protocol.
macOS
CrowdStrike tracked COOKIE SPIDER's SHAMOS variant of Atomic macOS Stealer hitting 300+ customer environments between June and August 2025 via malvertising + paste-this-into-Terminal social engineering (CrowdStrike, 20 Aug 2025).
500%

Increase in infostealer credential-log activity in 2024, per Fortinet's 2025 Global Threat Landscape Report. FortiGuard Labs tracked a 42% surge in stolen credentials offered on darknet forums — over 100 billion unique records (email, password, session tokens, MFA bypass data) traded and sold.

Source: Fortinet 2025 GTLR (28 Apr 2025)

Where the logs end up

Russian Market is the dominant stealer-log marketplace in 2026. Rapid7 Labs' October 2025 investigation found more than 180,000 infostealer logs offered for sale in H1 2025, with ~30,000 new "bots" listed every month at a standard price of ~$10 each. Geographic distribution: United States 26%, Argentina 23%, Brazil third. Top three vendors (Nu####ez, bl####ow, Mo####yf) account for over 80% of listings.

Parallel distribution runs through Telegram channels Group-IB formally tracks as "Underground Clouds of Logs" (UCL) — closed subscriber-only channels where operators drop fresh stealer-log archives daily. Russian-language criminal slang for these channels: облака логов ("clouds of logs") or стачи стилер логов.


Part 2 — The Ransomware Leak-Site Wall

Every major ransomware operation in 2026 runs a Tor-hosted leak site where unpaid victims' data is dumped. FortiRecon's ACI module monitors these sites continuously — the product page has a named "Ransomware Intelligence" feature that tracks threat-actor activities, past and potential targets, and supply-chain vendor exposure.

LockBit / LockBit 3.0 / LockBit 5.0

RaaS Disrupted Feb 2024
Scale
CISA advisory AA23-165A: ~1,700 US attacks since Jan 2020, $91M+ in paid ransoms. Q1 2023: 1,653 alleged victims on LockBit leak sites.
Cronos
20 February 2024 — UK NCA-led Operation Cronos seized 34 servers across 3 countries, infiltrated LockBit's affiliate panel, identified 194 affiliates, recovered 1,000+ decryption keys. LockBit was responsible for 25% of global ransomware attacks in 2023–2024 per NCA (NCA press release).
Unmasked
May 2024: Russian national Dmitry Khoroshev (alias "LockBitSupp") sanctioned by UK FCDO, US OFAC and Australian DFAT. Data seized from LockBit systems showed 7,000+ attacks built between June 2022 and February 2024; at least 2,110 victims forced into negotiation; monthly UK attack rate dropped 73% post-Cronos.

ALPHV / BlackCat

RaaS (Rust) Exit scam Mar 2024
Advisory
AA23-353A (rev 27 Feb 2024): since mid-December 2023, of the nearly 70 leaked victims, healthcare was the most commonly victimised sector — a deliberate reprisal after the FBI disruption in early December 2023.
TTPs
Advanced social engineering posing as IT/helpdesk staff to phish credentials (T1598). Brute Ratel C4 and Cobalt Strike beacons. Evilginx2 for MFA/session-cookie theft. Files renamed RECOVER-(seven-digit).txt.
Exit
March 2024: after a ~$22M ransom from UnitedHealth / Change Healthcare, ALPHV operators allegedly absconded with the full payment — affiliate side disclosed on RAMP. No US government press release confirms the exit scam; disclosure is via Krebs on Security / Recorded Future / Fabian Wosar.

Cl0p / CLOP / TA505

RaaS → Data theft Mass exploit
Advisory
AA23-158A: MOVEit campaign exploited CVE-2023-34362 from 27 May 2023 via the LEMURLOOT web shell. GoAnywhere MFT campaign (January 2023, CVE-2023-0669) hit ~130 victims in 10 days. Cleo LexiCom follow-up (Dec 2024, CVE-2024-50623 / CVE-2024-55956) added victims through 2025.
Fortinet
FortiRecon tracked 419 Cl0p victim organisations on the ransomware leak site as of 15 July 2023 — a first-party FortiGuard Labs stat (FortiGuard Labs blog, 21 Jul 2023). This is the FortiRecon ACI ransomware-intel feature in action.

Akira

RaaS (Conti lineage) Active 2026
Proceeds
AA24-109A (rev 13 November 2025): "As of late September 2025, Akira ransomware has claimed approximately $244.17 million (USD) in ransomware proceeds." Possible connections to defunct Conti group; aliases include Storm-1567, Howling Scorpius, Punk Spider, Gold Sahara.
CVEs
Initial access via SonicWall CVE-2024-40766 (heavily leveraged), Cisco ASA/FTD CVE-2020-3259 and CVE-2023-20269, VMware ESXi CVE-2024-37085, Veeam CVE-2024-40711. June 2025: first Akira incident encrypting Nutanix AHV VM disk files — new TTP tracked in the Nov 2025 advisory update.
Speed
"In some incidents, Akira threat actors exfiltrated data in just over two hours from initial access" (AA24-109A).

Play / PlayCrypt

Closed RaaS Active 2026
Scale
AA23-352A (rev 4 Jun 2025): ~900 affected entities as of May 2025; Play was among the most active groups in 2024.
Access
Initial access via FortiOS CVE-2018-13379 and CVE-2020-12812, Microsoft Exchange ProxyNotShell. January 2025 onwards: RMM tool SimpleHelp CVE-2024-57727. Unique TTP: Play ransomware binary is recompiled for every attack, producing unique hashes — AV/EDR signatures are useless.
Victim intake
Each victim gets a unique @gmx.de or @web[.]de email; portion of victims contacted via telephone with explicit threats.

Interlock

RaaS (2024+) Education focus
Advisory
AA25-203A (July 2025): first observed September 2024; targets North American education organisations.
TTPs
MintLoader / ClickFix campaigns, custom infostealer move.dll targeting Chrome/Firefox/Edge/Brave/Opera, exfiltrates via AZcopy (>250 GB). Zero-day CVE-2025-61155 — "Hotta Killer" gaming anti-cheat driver used to kill security tools (FortiGuard Labs, Jan 2026).
194 affiliates · 7,000+ attacks

LockBit's internal books, seized by UK NCA in Operation Cronos, revealed 194 active affiliates and 7,000+ attacks between June 2022 and February 2024. 148 affiliates built attacks; 119 engaged in negotiations; 75 of those never negotiated a successful payment. Post-disruption active affiliate count: 69.

Source: NCA — LockBit leader unmasked and sanctioned (May 2024)

Part 3 — The Telegram Criminal Channel Ecosystem

Post-2022, criminal activity migrated from dark-web forums to Telegram at an extraordinary rate. KELA's 2023 research documented Telegram channels carrying combolists, Clouds of Logs, stealer-log distribution, card shops, initial-access-broker offerings and ransomware leak dumps.

The Durov arrest and its aftermath

Pavel Durov, Telegram's founder, was arrested on 24 August 2024 at Le Bourget Airport, Paris. The Paris Public Prosecutor's Office (Section J3 – JUNALCO, Fight against Cybercrime) indicted him four days later on 12 charges including complicity in distribution of child exploitation material, drug trafficking, running an online platform permitting illicit transactions, money laundering, providing cryptographic services to criminals, and refusal to communicate information to authorities. Prosecutor Laure Beccuau cited Telegram's "almost total failure to respond to judicial requests." Durov was released on €5 million bail, barred from leaving France.

On 23–24 September 2024 Telegram amended its Terms of Service and privacy policy to share user IP addresses and phone numbers with law enforcement in response to valid legal requests — previously reserved only for terrorism cases. Telegram's 2024 transparency report disclosed user data on 2,253 US users (a dramatic jump from near-zero in prior years).

362×

Cybercriminals still use Telegram 362 times more than Signal + Discord combined, four months after Durov's arrest. KELA counted 246,903 cybercriminal links shared on Telegram per month vs. roughly 682 combined across Signal and Discord. Announced migrations (Bl00dy Ransomware Gang, Team ARXU, Al Ahad) largely returned within weeks.

Source: KELA — "Three Months After the Storm" (18 Dec 2024)
43.5 million

Telegram channels and groups blocked in 2025 — an 8–10× increase in daily takedown velocity post-Durov. Daily takedowns climbed from 10,000–30,000/day to 80,000–140,000/day with peaks over 500,000 in a single day. Check Point Research estimates ~20% of blocked channels were tied to criminal activity affecting businesses.

Source: Check Point Research — Telegram Crackdown 2026 (18 Mar 2026)

Evasion tactics observed by Check Point's Exposure Management team: "Request to Join" gating to block moderation bots, pre-positioned backup channels for instant reconstitution, bio disclaimers claiming compliance. Over a three-month monitoring window, Check Point counted approximately 3 million Telegram invite links shared across underground environments. Discord accounted for less than 6% of the same volume.


Part 4 — The Forum Graveyard

Law-enforcement pressure on dark-web forums intensified between 2022 and 2026. The list of takedowns reads like a who's-who of criminal-marketplace history.

Hydra Market

5 Apr 2022

Russia-based darknet market. $5.2 billion in cryptocurrency received since 2015. 17M customers, 19,000+ seller accounts. German BKA seized servers and ~$25M in Bitcoin. US Treasury OFAC sanctions + DOJ indictment of admin Dmitry Pavlov (press release JY0701). 80% of 2021 darknet market crypto volume at takedown.

RaidForums

Feb 2022

Operation Tourniquet (NCA-led). Sold access to 10+ billion consumer records from 2016. Alleged admin Diogo Santos Coelho arrested in UK 31 Jan 2022 at US request. BreachForums became de-facto successor within weeks.

Genesis Market

5 Apr 2023

Operation Cookie Monster (Eurojust + FBI + 13 countries). 100+ arrests, 200+ property searches. At takedown, Genesis advertised credentials from ~460,000 devices. Per Recorded Future, Russian Market listings paused for one week then resumed — 15% above pre-takedown level by mid-May.

BreachForums (1st)

Mar 2023

Admin Conor Fitzpatrick ("pompompurin") arrested EDVA. Forum had 340,000+ members. Initial 20-year supervised release overturned; resentenced to 3 years prison on access-device-fraud + CP possession charges.

BreachForums (2nd)

15 May 2024

FBI seizure of clearnet + onion sites + Telegram channel. Relaunched June 2023 by ShinyHunters + Baphomet. DOJ described: "clear-net marketplace for cybercriminals to buy, sell, and trade… stolen access devices, means of identification, hacking tools, breached databases."

BreachForums (3rd — IntelBroker)

Feb 2025

Kai West (25, British national) unmasked as "IntelBroker"; arrested in France Feb 2025; identity published 25 Jun 2025. Charged SDNY with conspiracy to commit computer intrusions, wire fraud — potential 25-year sentence. $25M+ alleged damages. Breaches linked: Europol, DC Health Link, Cisco, GE, AMD, HPE, Nokia. Four French nationals also arrested under handles ShinyHunters, Hollow, Noct, Depressed.

XSS.is / DaMaGeLaB

22 Jul 2025

Admin "Toha" arrested in Kyiv by Ukrainian SBU Cyber Department (French Police + Paris Prosecutor + Europol). 50,853 members, 110,000+ threads, €7M estimated profits (Europol). Clearweb seized; onion survived. Former moderators launched DamageLib on 3 Aug 2025 (KELA: 33,487 users in first month, but only 248 threads).

RAMP (ransomware forum)

Jan 2026

FBI + SDFL US Attorney + DOJ CCIPS seizure. Ransomware affiliate recruitment forum founded July 2021. Used by LockBit, ALPHV, Conti, DragonForce, Qilin, Nova, Radiant, RansomHub for affiliate coordination.

The pattern: disruptions don't eliminate criminal activity. They redistribute it. After XSS, Exploit.in traffic rose ~24% (Intel 471). After BreachForums, ShinyHunters relaunched. After Genesis, Russian Market absorbed the demand. The Fortinet 2025 GTLR's 100-billion-record credential number is an aggregate across this fragmented, constantly-rebuilding ecosystem.


Part 5 — What FortiRecon ACI Actually Monitors

FortiRecon is Fortinet's "AI and Human gathered intelligence-powered Continuous Threat Exposure Management service" (datasheet, verbatim). It was named Overall Leader, Market Leader and Innovation Leader in the 2025 KuppingerCole Leadership Compass for Attack Surface Management. Four modules, of which three intersect with the dark-web economy above:

Module · ACI

Adversary-Centric Intelligence

  • Ransomware intelligence — monitors LockBit, ALPHV, Cl0p, Akira, Play and successors; reports past and potential targets and TTPs relevant to your profile and vendors
  • Stealer infections — detects Lumma, RedLine, Vidar, StealC and others harvesting your employees
  • Data leakage intel — credential leaks, stealer-log drops, data-for-sale listings
  • Card-fraud monitoring — credit/debit cards on darknet markets (Financial Services add-on)
  • MITRE ATT&CK view — TTP mapping against your sector
  • Supply-chain / vendor risk — 25 vendors monitored by default (expandable)

Module · Brand Protection

Brand & Executive Protection

  • Typosquatting + lookalike domain detection
  • Rogue mobile-app monitoring (iOS/Android app stores)
  • Brand + executive impersonation (LinkedIn, X, Telegram, Facebook)
  • Data leak in code repositories
  • Open cloud-bucket detection
  • FortiGuard Labs takedown service — 2 default per account, add-ons via FRN-TKD-* SKUs

Module · EASM

Attack Surface Management

  • Continuous external asset discovery (domains, sub-domains, ASNs, IPs)
  • Alerts on exploitable vulnerabilities, mis-configurations, SSL cert issues, exposed DB services
  • Internal Attack Surface Management via lightweight scanner container
  • Web-application security assessment (SQLi, XSS, RCE; auto-discovers exposed APIs)
  • Supply-chain and subsidiary monitoring

Module · Orchestration

Security Orchestration

  • Pre-built playbooks: Vulnerability Intelligence, Ransomware Intelligence, Malware Intelligence, APT, CERT Advisories
  • Visual drag-and-drop playbook builder + low-code mode
  • 100 playbook executions/month default; stackable add-ons
  • Integrates with FortiGate, FortiSOAR, FortiSIEM, FortiDAST; AWS / Azure / GCP; Teams, Slack, email

A concrete example of ACI in action: when Fortinet's own July 2023 Cl0p roundup states "As of July 15th, 2023, Fortinet's FortiRecon service listed 419 victim organisations on the Cl0p ransomware data leak site" — that 419 is a FortiRecon ACI count. The product doesn't scrape leak sites manually; it ingests the feed continuously, maps to MITRE ATT&CK, and alerts when a customer or their supply-chain vendor appears.


Part 6 — India-Specific Reality Check

16 billion

Login credentials exposed globally and flagged by CERT-In in advisory CIAD-2025-0018 on 23 June 2025. Consolidated from 30 distinct sources, "predominantly acquired through info stealer malware attacks" per CERT-In's own wording. Any Indian enterprise's users are almost certainly represented in this dataset somewhere.

Source: CERT-In Advisory CIAD-2025-0018
CERT-In Ransomware Report 2024

Manufacturing 30.14%

Manufacturing absorbed 30.14% of reported Indian ransomware incidents in 2024. LockBit alone responsible for 61.8% of tracked attacks against Indian targets.

Check Point India 2025

44,000+ Lumma infections

Indian Windows systems compromised by Lumma Stealer in March–May 2025. RisePro, Vidar and RedLine also active. Indian organisations averaging 2,000+ cyberattacks per week in 2025 — well above global average.

Recorded Future Insikt

India 2nd globally

Across the full infostealer dataset (Aug 2023 – Feb 2024), "Brazil overwhelmingly dominated the counts for the highest number of infostealer logs, followed by India." (Caught in the Net, 2 Jul 2024.)

Group-IB (2023)

12,632 ChatGPT creds

India accounted for 12,632 stolen ChatGPT credentials on illicit markets between June 2022 and May 2023 — the highest count in Asia-Pacific. The credential file typically came from a Lumma or RedLine stealer log.

CloudSEK (Mar 2026)

Digital Lutera UPI fraud

Toolkit distributed across 20+ Telegram groups, each with 100+ members. One monitored group: ₹25–30 lakh fraudulent transactions in two days. APK masquerades as traffic-fine / wedding invitation, forwards SMS/OTP to attacker Telegram channel, registers victim's UPI on attacker device.

CloudSEK (Jan 2024)

750M subscriber records

1.8TB dataset of ~750 million Indian mobile subscribers (name, number, address, Aadhaar) listed for $3,000 on dark web by actors "CyboDevil" and "UNIT8200".

The AIIMS Delhi attack — still the reference Indian incident

23 November 2022: All India Institute of Medical Sciences (AIIMS) Delhi ransomware attack. More than 100 servers encrypted; approximately 40 million patient records impacted. Ransom demand reported at roughly ₹200 crore (~$24.5M) in cryptocurrency. CERT-In's investigation identified payloads including Wammacry variant, Mimikatz and a trojan. ProtonMail addresses used by attackers ("dog2398" and "mouse63209") were generated in Hong Kong the first week of November 2022. CERT-In's initial analysis flagged possible foreign state-actor involvement. Systems were restored on 12 December 2022. The incident remains the anchor case for Indian health-sector cybersecurity planning.

Other 2024–2025 named Indian victims (via public reporting): Polycab India, Motilal Oswal, SPARSH Hospital, ASRAM Medical College, Lupin Limited, NewGen. Roughly two dozen ransomware brands attacked Indian targets in January–November 2025 (Check Point India 2025).

💡 Why this changes the DPDPA conversation

Under the Digital Personal Data Protection Act 2023, "personal data breach" triggers notification obligations. If an employee's Lumma-infected home PC has leaked their SSO cookies into a Russian Market listing, and those cookies reach corporate SSO and touch Indian data-principal records — the breach detection clock starts from the time you knew, not from the time the credential was sold. Dark-web monitoring is the mechanism that lets you know.


Part 7 — If You Find Yourself on the Dark Web: A Playbook

FortiRecon ACI detects exposure. The value of the detection depends entirely on what your team does next. This is the playbook Ogma runs.

1

Verify the source

Analyst confirms the leak is genuine — not a recycled breach from 2019, not a typosquat detection, not a false positive. Timestamp and original paste-site or channel captured as evidence.

2

Scope the exposure

Which users, which services, which data. Check if the same stealer log contains cookies for SSO, VPN, GitHub, Okta, admin consoles. Cookies are worse than passwords because they bypass MFA.

3

Contain

Force password reset, kill active sessions (revoke SSO tokens), invalidate OAuth refresh tokens. If admin credentials are in play, quarantine the endpoint and do an IR sweep for persistence. Cycle API keys and SSH keys that might be in the log.

4

Takedown where applicable

FortiGuard Labs takedown for fake domains, phishing pages, rogue mobile apps, social-media impersonation. Two takedowns per account included by default; more via add-on. Typical resolution time: days, not weeks.

5

Notify — DPDPA, CERT-In, regulators

If personal data of Indian data principals is involved, prepare Data Protection Board notification. CERT-In has a 6-hour incident reporting requirement for certain categories. Maintain the evidence package for the auditor.

6

Root-cause the infection

Most stealer-log leaks trace back to a personal device. Was the compromised user using corporate SSO on a home laptop? Was the browser profile synced? Policy updates and endpoint hardening prevent recurrence.


✅ Key Takeaways

  1. The dark web in 2026 is an economy — infostealer log drops, ransomware leak sites, Telegram criminal channels — not a single hidden corner.
  2. Infostealers are the credential pipeline. Microsoft hit 394,000 Lumma infections in 60 days in 2025. Russian Market offered 180,000+ logs in H1 2025. India ranks second globally by volume.
  3. Ransomware hasn't stopped — it's reorganised. Operation Cronos identified 194 LockBit affiliates and 7,000+ attacks in 20 months. Akira alone claimed $244M by late 2025.
  4. Telegram, even under pressure, remains the centre of gravity. KELA measured 362× more criminal activity on Telegram than on all alternatives combined after the Durov arrest.
  5. Indian exposure is not theoretical: CERT-In flagged 16 billion exposed credentials; Check Point counted 44,000+ Indian Lumma infections in one quarter; 20+ Telegram groups run active UPI-fraud operations.
  6. FortiRecon ACI is the industry's top-ranked platform for exactly this category of threat — Overall + Market + Innovation Leader in the 2025 KuppingerCole Leadership Compass for ASM.

🔍 Free — no credit card

Find out what's already out there about your organisation

Ogma will run a free one-shot FortiRecon scan against your primary domain and email range and deliver a written exposure report within 48 hours. If anything's leaked, you'll know. If it's clean, you'll have a baseline. Either way, you'll know more than you do right now.

📡  Request a free exposure scan See the FortiRecon service →

🔥 Authorised Fortinet Partner

Talk to the threat team

Ogma Consulting runs FortiRecon as a managed service for Indian BFSI, manufacturing and government estates. NSE7-certified engineers, 24×7 analyst-verified alerts, India-context Hindi/regional-language coverage, FortiGuard Labs takedown support, DPDPA breach-notification readiness.

✉  Write to [email protected] 📞  +91 80 0979 0979

Stay ahead of cyber threats

One short email a week — curated Indian cybersecurity news, Fortinet releases, DPDPA updates. No fluff.


Cato Firewall as a Service
Cato ZTNA — Zero Trust Network Access
Cato SASE Solution