Skip to content
FortiBleed Campaign Links Credential Theft to Ransomware Operations

FortiBleed Campaign Links Credential Theft to Ransomware Operations

First seen 2 Jul 2026, 18:59 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 3, 2026 at 18:59 UTC

The FortiBleed campaign has been linked to two ransomware groups, INC Ransom and Lynx, through an operational security lapse that revealed one actor's simultaneous access to both groups' negotiation panels. This campaign targeted over 430,000 Fortinet firewalls, successfully harvesting credentials from at least 30,000 devices. Researchers confirmed admin-level access on 409 targets, with ransomware deployment occurring on 12 of those. The attack exploited SSL VPN authentication hashes, utilizing a 45-GPU cluster for cracking. The findings indicate that FortiBleed is not merely a credential theft operation but a precursor to ransomware attacks, significantly raising the stakes for organizations using FortiGate infrastructure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-06-17
FortiBleed campaign disclosed
The campaign targeted over 430,000 Fortinet firewalls, harvesting credentials and exploiting SSL VPN authentication.
Theregister
2026-07-02
Link between FortiBleed and ransomware confirmed
Research revealed a single operator linked to both INC and Lynx ransomware groups, indicating direct ties to ransomware deployment.
Darkreading
2026-07-02
Admin-level access confirmed on multiple targets
Attackers achieved admin-level access on 409 targets, completing the full attack chain on 354 of them.
Theregister

More articles in this cluster (4)

Following this threat?

Track Inc Ransom in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed