HomeSecurityFortiBleed Foreign Office: UK Credentials on the Dark Web

FortiBleed Foreign Office: UK Credentials on the Dark Web

The FortiBleed Foreign Office, as the escalation of the notorious FortiBleed that was revealed last month and has already affected over 70,000 devices in 194 countries, is now being called. According to reports, credentials belonging to British government officials and Foreign Office are now being sold on the dark web, causing alarm in the cybersecurity community.

The case is directly linked to the findings previously presented by CISA , however the new escalation now directly concerns British government infrastructure. According to ITPro, analysis by threat intelligence firm SOCRadar now attributes the attack to the Lynx/INC.

How the FortiBleed campaign evolved

The attack targets Fortinet VPN and firewall that are exposed to the internet, leveraging third-party credential harvesting techniques. Security researcher Volodymyr Diachenko was the first to spot the threat when he uncovered a massive database of stolen credentials.

Speaking to The Telegraph, Diachenko said that these credentials could give malicious actors access to the “core networks” of the Foreign Office, as well as other British government departments. This statement highlights the scale of the risk, as it is not just about individual user accounts, but access to critical network infrastructure.

Since the attack was first revealed last month, the number of affected devices has skyrocketed to over 70,000 across 194 countries, making it one of the most extensive credential theft campaigns recorded across network devices this year. The geographic spread, combined with the targeted nature of the latest phase against state actors, suggests that the group behind the attack is operating in an organized and systematic manner.

FortiBleed Foreign Office Fortinet credential theft

See also: CISA warns about FortiBleed – 86,644 FortiGate devices exposed

FortiBleed Foreign Office: The Foreign Office in the crosshairs and the £40,000 per credential

The most worrying aspect of the new phase is the pricing of the stolen credentials. Some privileged credentials belonging to Foreign Office being sold on the dark web for up to £40,000 each. This figure suggests that buyers are realising the high value of the access these credentials offer, likely at administrator or privileged account level.

The case is not limited to the Foreign Office. According to a report in The Telegraph, credentials belonging to NHS hospitals, energy companies and local councils in Britain were also found in the same illegal database. The fact that such different sectors of critical infrastructure appear in the same database reinforces the picture of a broad, horizontal campaign of credential harvesting, rather than a single, targeted breach.

The sale of government credentials at such high prices is an indication that the perpetrators behind the attack know their market well: government agencies, ransomware groups, and possibly state-sponsored actors are potential buyers of such privileged accounts, especially when they offer access to sensitive diplomatic and government networks.

Performance at Lynx/INC and the "credential factory"

SOCRadar ’s analysis officially attributed the attack to the Lynx/INC ransomware group, an attribution that SecNews has previously analyzed . This connection places the new escalation in the context of a broader ransomware ecosystem, where credential theft acts as a preparatory stage for future extortion attacks.

Adam Marrè, CISO of cybersecurity firm Arctic Wolf, described the attackers’ operation in particularly alarming terms. He said, “This major breach of email accounts of British government officials and Foreign Office employees abroad is the latest development in the ongoing FortiBleed attack.” Arctic Wolf’s threat intelligence team found that the attackers had set up a “highly sophisticated and repeatable credential factory” — a highly sophisticated “factory” for producing stolen credentials.

He warned that, "while today it is the Foreign Office that has been affected, the risk to every organization has increased exponentially," implying a domino effect on other government departments and local authorities.

Fortinet responds to credential harvesting campaign

See also: FortiBleed: Credential Theft Linked to INC and Lynx Ransomware

Fortinet's reaction and the disagreements

Fortinet responded to the reports by describing the case as “a reported third-party credential-harvesting campaign targeting Fortinet firewalls and VPN gateways.” The company stressed that it constantly monitors activity on the dark web and is committed to protecting its customers .

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

However, Fortinet said that, according to its initial analysis, the leaked data is “likely a resharing of data from previous incidents, as well as the result of brute forcing of credentials, and not related to any current incident or advisory.” In other words, the company is distancing itself from the idea that this is a new, active breach of its systems.

This position contradicts the findings of Hudson Rock, which had previously analyzed the campaign in detail in a publication. Hudson Rock argued that the attack extends “beyond simply credential reuse,” noting that hundreds of organizations are believed to have been affected. Fortinet had already disputed some of Hudson Rock’s claims when the campaign first emerged last month, insisting that the exposed credentials did not come from a new breach and that customers who follow security best practices remain protected.

What should Greek organizations do?

While the current escalation primarily concerns UK government agencies, the scale of the problem — over 70,000 devices across 194 countries— means that no organization using Fortinet equipment can afford to be complacent. The SecNews technical team recommends immediately checking access logs on VPN and firewall gateways, looking for signs of unauthorized connections, and confirming that all Fortinet devices are running the latest, most up-to-date firmware versions.

Particular attention should be paid to changing credentials for accounts with privileged access, as well as enabling MFA at all entry points. Given that the same infrastructure has been linked to ransomware groups such as Lynx/INC, early detection can prevent the transition to a full-blown extortion attack. The SecNews editorial team will continue to monitor developments, as the FortiBleed shows how quickly a credential harvesting campaign can turn into a national security issue.

See also: Fancy Bear hits Greece: Russian espionage in the Hellenic National Defense General Staff

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS