← BACK TO FEED
TAG

initial access broker1 articles

FortiBleed Credential Harvest Is Directly Feeding INC and Lynx Ransomware Operations

The FortiBleed campaign, a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls across 150 countries, has been directly linked to the deployment of INC Ransom and Lynx ransomware. Active since at least February and likely run by a Russian initial access broker involving around 20 individuals, the operation has compromised over 110 million credentials and resulted in ransomware attacks on 12 organisations, with hundreds of endpoints encrypted. SOCRadar confirmed the connection after an operational security mistake by the attackers exposed internal files, revealing a single operator working both ransomware negotiation panels using infrastructure tied to the FortiBleed campaign.

10 Jul 2026