Skip to content
FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs

FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs

Darkreading •Rob Wright • July 2, 2026

After gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug.

The initial access broker (IAB) operation behind the credential-harvesting FortiBleed campaign is working in concert with ransomware actors, indicating the victims of the massive operation are now facing an even greater threat.

Research published by SOCRadar this week connects FortiBleed actors with two ransomware-as-a-service (RaaS) gangs, Inc Ransom and Lynx. SOCRadar researchers discovered an operator behind the campaign's infrastructure that was actively logged into the ransom negotiation panels for both groups, and "engaging directly with ransom demands."

"Finding a single operator working both panels, using infrastructure traceable back to FortiBleed, is the clearest evidence yet that FortiGate credentials harvested through this campaign are being handed off, or used directly, for ransomware deployment," according to the SOCRadar blog post .

The connection to ransomware gangs marks the latest development in this saga. The attacks against insecure Fortinet FortiGate firewalls were initially discovered last month by security consultant Volodymyr "Bob" Diachenko. SOCRadar then later found that the attacks were part of a global campaign it dubbed "FortiBleed," which had compromised thousands of devices and used a Golang-based sniffer to turn firewalls into credential stealers .

The initial-access campaign targeted 430,000 FortiGate devices across the globe. SOCRadar said the FortiBleed sniffer is currently installed on approximately 12,000 FortiGate firewalls, though research indicated the IAB had credentials for more than 30,000 devices.

SOCRadar's findings stemmed from an "operational security lapse" in the FortiBleed campaign's infrastructure, which allowed researchers to gain access to the IAB operation's internal files, logs, and operational documentation. In addition to the FortiBleed operator's activity, SOCRadar's Threat Research Unit (STRU) found an Inc-linked open directory that contained datasets with overlapping victims.

The STRU also discovered an internal tracking document that contained the campaign's list of FortiGate targets , including data which credentials were used, which networks were accessed, and whether ransomware was deployed.

The STRU found that threat actors had achieved admin-level access on 409 targets. "On 354 of those, the actor completed the full attack chain: VPN compromise, access to the domain controller, and domain admin," according to the vendor. "STRU has confirmed at least 12 ransomware deployments stemming from this access, with hundreds of endpoints encrypted across affected organizations."

SOCRadar chief information security officer (CISO) Ensar Seker tells Dark Reading that while the company has not yet seen widespread ransomware deployment directly tied to FortiBleed attacks, "access to perimeter security devices can create a clear pathway for ransomware groups, so organizations should treat exposure as a serious pre-ransomware intrusion risk."

To date, he says most of the activity we have observed is "more consistent with credential theft, victim profiling, access brokering, and data theft-extortion risk," with SOCRadar's current assessment being that the IAB group is separate from the Inc and Lynx RaaS gangs, who are likely paying for the access.

"The evidence points to an access-supply layer where compromised Fortinet environments and related victim data are being collected, validated, and potentially monetized or passed downstream," he says, with Inc and Lynx acting as the downstream users of that access and data rather than the initial actors behind the compromised devices.

SOCRadar's research also noted that the FortiBleed IAB group, which while so far unnamed is known to be a structured operation with around 20 people and a small group of core operators, has more up its sleeve besides credential harvesting — namely, "at least one" zero-day vulnerability , according the report.

The undisclosed zero-day was not named in the report, but in emails to media outlets SOCRadar confirmed that the affected vendor is Nextcloud, and that threat actors tied to FortiBleed were actively exploiting the bug to expand zero-day access.

Dark Reading contacted Nextcloud for . Christoph Weissthaner, senior communications manager at Nextcloud, says the company has not been by SOCRadar. "We run a public bounty program and have not yet received a report of such a kind. When learning potential issues, we will fix them ASAP," Weissthaner says.

Seker says the STRU assesses the Nextcloud zero-day activity is associated with the "access-brokering/intrusion phase" of FortiBleed rather than the Inc and Lynx attacks: "In other words, the exploitation appears to support initial compromise or access expansion, while the ransomware brands may represent possible downstream monetization channels."

SOCRadar said it will continue investigating the activity to validate attribution and will present further analysis in a forthcoming white paper.

Senior News Director, Dark Reading

Rob Wright is a longtime reporter with more than 25 years of experience as a technology journalist. Prior to joining Dark Reading as senior news director, he spent more than a decade at TechTarget's SearchSecurity in various roles, including senior news director, executive editor and editorial director. Before that, he worked for several years at CRN, Tom's Hardware Guide, and VARBusiness Magazine covering a variety of technology beats and trends.

Prior to becoming a technology journalist in 2000, he worked as a weekly and daily newspaper reporter in Virginia, where he won three Virginia Press Association awards in 1998 and 1999. At TechTarget and Dark Reading, he has won several Azbee awards, including the 2026 National Silver Award for a series on vibe coding.

At Dark Reading, Rob currently covers security operations, cloud security, and Internet infrastructure. He has a keen interest in malvertising activity and the certificate authority industry, and has written extensively on both topics. He graduated from the University of Richmond in 1997 with a degree in journalism and English. A native of Massachusetts, he lives in the Boston area.

The State of Cloud Security: The Latest Challenges

The total economic impact™ of Snyk

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything

Practical Zero Trust Implementation on a Budget in the Age of Mythos

Building a Risk Based Vulnerability Management Program

Threat Hunting That Gets Big Results Despite Small Budgets

Say Yes to AI: Securing Innovation Without Compromise