The FortiBleed credential theft campaign has been directly linked to INC and Lynx ransomware operations, with an operator found accessing negotiation panels for both groups while using stolen FortiGate credentials to facilitate ransomware deployments. SOCRadar's investigation revealed the campaign targeted around 430,000 FortiGate firewalls globally, harvesting over 110 million credentials, with at least 12 confirmed ransomware deployments resulting in hundreds of encrypted endpoints. Evidence suggests the operation is run by an approximately 20-person Russian-speaking group, likely acting as an initial access broker, with signs they may be expanding their targeting beyond Fortinet devices to Citrix infrastructure.