FortiBleed Gang Moonlights for INC and Lynx Ransomware as Credential Haul Reaches 110 Million
The FortiBleed operation, the mass Fortinet credential theft campaign that surfaced last month, has been formally linked to two active ransomware groups: INC Ransom and Lynx. Threat intelligence firm SOCRadar published its findings Wednesday, and the picture it paints is not pretty.
The headline finding is that an operator with access to FortiBleed's backend was caught logged into negotiation panels for both INC Ransom and Lynx simultaneously. Victims listed in INC Ransom's panel overlapped with targets from the FortiBleed dataset. That is the first time mass FortiGate credential theft has been tied directly to ransomware deployment with any real evidence behind it.
SOCRadar tracked scanning activity against roughly 11,250 FortiGate portals across more than 150 countries. Of those, 409 resulted in confirmed admin-level access, 354 completed the full attack chain, and at least 12 have ended in ransomware deployment, with hundreds of endpoints encrypted across affected organisations.
The broader campaign is thought to have swept up credentials from around 430,000 FortiGate firewalls globally, yielding over 110 million credentials. The attackers got caught because someone on their side left a server exposed to the open internet, the kind of operational security failure that haunts threat actors and delights researchers.
The Golang-based packet sniffer at the heart of the operation, which passively hoovers up credentials and authentication data from live network traffic, is estimated to have been installed on around 12,000 Fortinet devices. That is a subset of everything targeted, suggesting a deliberate prioritisation of high-value systems.
One of around 200 newly identified servers tied to FortiBleed's infrastructure gave SOCRadar visibility into internal files, logs, scripts, and operational documentation. SOCRadar's CISO Ensar Seker described it as a staging and coordination server used to manage the credential harvesting at scale, not a phishing lure or anything victims directly touched.
The tooling, working patterns, and logs all point toward a Russian-speaking threat actor operating as an initial access broker. Manufacturing, technology, and logistics firms in Latin America and Asia Pacific appear to have been the primary targets. An internal document recovered from the exposed server suggests the operation involves roughly 20 people with defined roles, a small core of senior operators running high-impact intrusions, supported by specialists and admin staff.
Things get more uncomfortable from there. SOCRadar says the group is believed to hold at least one zero-day affecting Nextcloud, and is coordinating with the vendor on disclosure. It also found Citrix-related artefacts in the infrastructure, including a target list of around 29,000 IP addresses and 37 domains tied to Citrix environments. No confirmed large-scale credential harvesting against Citrix has been proven yet, but the reconnaissance is clearly already underway.
Seker's advice is blunt: if your organisation runs internet-facing Citrix infrastructure, check your authentication logs now, rotate any credentials that could have been exposed, enforce MFA, and watch for unusual login activity.
Separately, eSentire has reported active exploitation of a critical Fortinet FortiClient EMS vulnerability (CVE-2026-35616, CVSS 9.1) to drop a credential stealer called EKZ Stealer. The malware targets Chromium-based browsers and Firefox, then exfiltrates the haul via PowerShell. The victim in this case was an organisation in the energy, utilities, and waste sector.
Fortinet continues to be a very productive hunting ground for financially motivated attackers. Whether your devices are patched is no longer the only question worth asking.