FortiBleed: Uncovering the Link to INC and Lynx Ransomware (2026)

In the ever-evolving landscape of cybersecurity, the discovery of the FortiBleed campaign has sent shockwaves through the industry. This financially-motivated attack, attributed to the INC and Lynx ransomware operations, has revealed a disturbing trend in the world of cybercrime. What makes this case particularly intriguing is the link between credential theft and ransomware deployment, a strategy that has never been directly confirmed before. The FortiBleed campaign, which targeted 430,000 FortiGate firewalls globally, showcases the sophistication and scale of modern cyber threats. The attackers' systematic approach, involving scanning for exposed devices and using known credential combinations, highlights the importance of robust security measures. What makes this attack even more concerning is the discovery of an operator with access to FortiBleed infrastructure who was logged in to both INC Ransom and Lynx negotiation panels. This finding suggests a potential collaboration or shared resources between these ransomware groups, which could have significant implications for organizations worldwide. The fact that the attackers were able to gather over 110 million credentials and deploy custom packet sniffers to passively gather authentication data from network traffic is a stark reminder of the vulnerabilities that exist in many networks. The large-scale credential-harvesting operation, which came to light last month, involved the threat actors systematically scanning the internet for exposed Fortinet devices, attempting to break into them using known credential combinations, and then deploying custom packet sniffers to passively gather credentials and other authentication data from network traffic. The campaign is assessed to have targeted 430,000 FortiGate firewalls globally, gathering over 110 million credentials in the process. The activity was exposed after an operational security error on the part of the attackers left a server containing credentials stolen from thousands of Fortinet appliances exposed on the internet. The Golang sniffer is estimated to have been installed on about 12,000 Fortinet devices, making it a subset of the total number of networking gear targeted. The implications of this attack are far-reaching, particularly for organizations in the manufacturing, technology, and logistics sectors in Latin America and the Asia Pacific regions. The discovery of an internal document that indicates it's an organized operation comprising about 20 people with a clear division of labor further emphasizes the sophistication and coordination of the attack. The threat actors are believed to be in possession of at least one zero-day vulnerability in Nextcloud, which could have significant implications for organizations that use this platform. The disclosure comes as eSentire observed threat actors exploiting a flaw in Fortinet FortiClient EMS (CVE-2026-35616) to deploy an information stealer called EKZ Stealer against a customer in the energy, utilities, and waste sector with the end goal of harvesting credentials from Chromium-based browsers and Firefox and exfiltrating them via PowerShell. This attack highlights the importance of staying vigilant and proactive in the face of evolving cyber threats. In my opinion, the FortiBleed campaign serves as a stark reminder of the need for organizations to invest in robust security measures and to stay informed about the latest threats and vulnerabilities. The collaboration between ransomware groups and the use of zero-day vulnerabilities are particularly concerning, and organizations must take steps to protect themselves against these threats. The discovery of the FortiBleed campaign has significant implications for organizations worldwide, particularly in the manufacturing, technology, and logistics sectors in Latin America and the Asia Pacific regions. The attack highlights the importance of staying vigilant and proactive in the face of evolving cyber threats, and organizations must take steps to protect themselves against these threats. The collaboration between ransomware groups and the use of zero-day vulnerabilities are particularly concerning, and organizations must take steps to protect themselves against these threats. The FortiBleed campaign serves as a stark reminder of the need for organizations to invest in robust security measures and to stay informed about the latest threats and vulnerabilities.

FortiBleed: Uncovering the Link to INC and Lynx Ransomware (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Terrell Hackett

Last Updated:

Views: 5528

Rating: 4.1 / 5 (72 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Terrell Hackett

Birthday: 1992-03-17

Address: Suite 453 459 Gibson Squares, East Adriane, AK 71925-5692

Phone: +21811810803470

Job: Chief Representative

Hobby: Board games, Rock climbing, Ghost hunting, Origami, Kabaddi, Mushroom hunting, Gaming

Introduction: My name is Terrell Hackett, I am a gleaming, brainy, courageous, helpful, healthy, cooperative, graceful person who loves writing and wants to share my knowledge and understanding with you.