HomeSecurityFortiBleed: Credential theft linked to INC and Lynx Ransomware

FortiBleed: Credential Theft Linked to INC and Lynx Ransomware

The FortiBleed campaign — one of the largest mass credential theft operations on record — is now directly linked to the INC Ransom and Lynx ransomware groups , according to new research from SOCRadar . For the first time, a direct connection has been documented between mass credential theft from Fortinet devices and the deployment of ransomware in targeted organizations. The revelation significantly upgrades the threat assessment and puts thousands of organizations worldwide on alert.

FortiBleed credential theft campaign linked to INC and Lynx ransomware

According to The Hacker News, SOCRadar has identified a group that is connected to the FortiBleed and to the negotiation panels of both groups — INC Ransom and Lynx. The victims shown in the INC Ransom bear similarities to data from the campaign, confirming the connection. This visibility was achieved through one of the 200 newly discovered servers associated with the FortiBleed infrastructure, which exposed internal files, logs, and operational documents.

See also: CISA warns about FortiBleed – 86,644 FortiGate devices compromised

The campaign was of impressive scale: researchers observed scanning activity on approximately 11,250 FortiGate portals in more than 150 countries. Administrator-level access was confirmed on 409 targets, while the full attack chain was successfully completed on 354 of them. At least 12 ransomware deployments have resulted from this access, resulting in hundreds of endpoints being encrypted in affected organizations.

FortiBleed: How the credential theft attack works

The FortiBleed campaign came to light last month when an operational security lapse on the part of the attackers left a server containing stolen credentials from thousands of Fortinet. The operation targeted a total of 430,000 FortiGate firewalls worldwide, harvesting over 110 million credentials. The threat actors systematically scanned the internet for exposed Fortinet, attempted to infiltrate using known credential combinations, and then installed custom packet sniffers to passively collect credentials and other identifying data from network traffic.

The sniffer, written in Golang, is estimated to have been installed on approximately 12,000 Fortinet devices. The use of Golang to develop the tool suggests a high level of technical expertise, as code in this language is difficult to detect and runs efficiently on multiple platforms. The tools, logs, and work schedules indicate that the activity is the work of a Russian-speaking threat actor likely acting as an initial access broker.

See also: AI Ransomware Abuses Chromium API on Windows and Android

FortiBleed - SecNews.gr

FortiBleed: Organized business with 20 people and zero-day vulnerability

An internal document discovered by SOCRadar reveals that it is an organized operation consisting of about 20 people with a clear division of labor. “A small core of primary operators leads most of the high-impact attacks, supported by specialists and support personnel,” the company said. The targeting focused primarily on the manufacturing, technology , and supply chain in Latin America and Asia-Pacific.

Particularly concerning is the finding that the threat actors are believed to possess at least one zero-day vulnerability in Nextcloud. SOCRadar said it is actively coordinating with the affected vendor to address the threat. Having a zero-day in their arsenal further elevates the group’s threat level, as it means they can exploit unknown vulnerabilities before patches are released.

In parallel, cybersecurity firm eSentire identified threat actors exploiting a vulnerability in Fortinet FortiClient EMS (CVE-2026-35616, CVSS score: 9.1) to deploy an information stealer called EKZ Stealer against a customer in the energy, utilities, and waste management sector. The ultimate goal was to collect credentials from Chromium-based browsers and Firefox and extract them via PowerShell. The critical CVSS score of 9.1 underscores the severity of the vulnerability and the need to apply security updates immediately.

See also: Ransomware 2026: 49% don't understand the attack before data is stolen

FortiBleed: Credential Theft Linked to INC and Lynx Ransomware

For organizations using Fortinet, the situation requires immediate action: verify logs for suspicious activity, change all administrator credentials, apply the latest security updates, and enable multi-factor authentication (MFA). The FortiBleed campaign proves once again that exposed networking devices are a prime target for ransomware seeking initial access to corporate networks.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS