News Room
16
Share
FortiBleed Campaign: INC and Lynx Ransomware Groups Exploit Massive FortiGate Credential Harvest
criticalThreat Intelligence

FortiBleed Campaign: INC and Lynx Ransomware Groups Exploit Massive FortiGate Credential Harvest

A massive credential harvesting campaign dubbed 'FortiBleed' has compromised hundreds of thousands of FortiGate firewalls. Threat actors INC and Lynx are actively leveraging this access to facilitate ransomware attacks.

16 September 2026Last updated 16 September 20264 min readOffSeq
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
Source:
OffSeq
Read Time:
4 min

Executive Summary

Security researchers have identified a widespread, high-impact campaign targeting FortiGate firewall infrastructure, now referred to as 'FortiBleed.' This operation has successfully harvested administrative credentials from hundreds of thousands of devices globally. The stolen access is being actively exploited by the ransomware-as-a-service (RaaS) groups INC and Lynx to gain initial entry into corporate networks, escalate privileges, and deploy ransomware payloads.

Threat Analysis

The FortiBleed campaign represents a significant escalation in the use of initial access brokers (IABs) to fuel the ransomware ecosystem. By targeting edge devices, attackers bypass traditional perimeter defenses. The campaign is attributed to a sophisticated Russian-speaking IAB operation that has successfully weaponized these credentials, providing a steady stream of high-value targets to affiliate-based ransomware groups. The overlap in victim sets between INC and Lynx suggests a coordinated effort to maximize the monetization of the harvested data.

Technical Details

Attackers are exploiting vulnerabilities and weak configurations in FortiGate portals to gain administrative control. Once inside, the threat actors perform lateral movement, often utilizing VPN compromise to establish persistent access. The attack chain typically culminates in domain admin privilege escalation, allowing the deployment of ransomware binaries. Forensic analysis indicates that the attackers are using custom scripts to automate the credential harvesting process, which has resulted in the compromise of hundreds of thousands of unique firewall instances.

Attribution Assessment

The campaign is currently attributed to a Russian-based initial access broker. The infrastructure used for the FortiBleed campaign shows clear links to the operational patterns of INC and Lynx. These groups have been observed sharing command-and-control (C2) infrastructure and utilizing similar post-exploitation toolsets, confirming a collaborative relationship between the broker and the ransomware operators.

Implications

The scale of the FortiBleed campaign poses a critical risk to organizations worldwide. With hundreds of thousands of firewalls potentially compromised, the window for remediation is narrow. Organizations that fail to rotate administrative credentials and patch vulnerable FortiGate devices are at immediate risk of double-extortion ransomware attacks, where sensitive data is exfiltrated prior to encryption.

Recommendations

  1. Immediate Credential Reset: All administrative passwords for FortiGate devices must be reset immediately, regardless of whether compromise is suspected.
  2. Patch Management: Ensure all FortiGate firmware is updated to the latest version to mitigate known vulnerabilities.
  3. Multi-Factor Authentication (MFA): Enforce strict MFA for all administrative access to edge devices.
  4. Network Monitoring: Implement enhanced logging and monitoring for VPN traffic and unusual administrative activity originating from firewall management interfaces.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo