Sophia
Hart

FortiBleed Credential Theft Linked to Lynx Ransomware Operations

Sophia Hart

Jul 3, 2026

7 min read

fortinet credential theft

TL; DR

  • FortiBleed is a reported Fortinet credential-theft campaign involving compromised FortiGate firewalls and VPN gateways.
  • BleepingComputer reported that SOCRadar linked FortiBleed infrastructure to INC and Lynx ransomware operations.
  • SOCRadar says attackers targeted more than 430,000 FortiGate firewalls and deployed sniffers on approximately 19,000 devices.
  • Security teams should treat exposed Fortinet and VPN credentials as potential ransomware precursor activity, not only firewall cleanup.

Fortinet credential theft has moved from an edge-device exposure story to a ransomware access concern. BleepingComputer reported that SOCRadar linked the FortiBleed campaign to INC and Lynx ransomware operations, raising the risk that stolen Fortinet and VPN credentials could support future network intrusions.

BleepingComputer reported that SOCRadar linked the FortiBleed campaign to the INC and Lynx ransomware operations, raising concerns that stolen Fortinet and VPN credentials could enable subsequent intrusion attempts.

Fortinet has said its initial analysis points to credential reuse and brute-force activity, not a new Fortinet vulnerability. The latest update does not change that distinction, but it adds a more serious operational concern: exposed edge-device credentials may become useful to ransomware access pipelines.

Improve credential theft detection with Hexnode XDR

What the Lynx Ransomware link changes

SOCRadar’s latest FortiBleed reporting adds a ransomware access angle to the credential-theft campaign.

The update matters because:

  • Ransomware infrastructure was identified in the investigation: According to BleepingComputer, SOCRadar linked the FortiBleed infrastructure to INC and Lynx ransomware operations.
  • The link came from campaign infrastructure: SOCRadar identified a Windows server used in the FortiBleed operation.
  • Ransomware panels were reportedly accessed: SOCRadar reported that browser sessions on that server accessed ransomware administration panels and negotiation dashboards containing victim chats.
  • The finding does not confirm ransomware impact for every victim: The reporting links infrastructure, not every affected FortiGate environment.
  • The response priority changes: Exposed Fortinet device and VPN credentials should be treated as possible initial access material, not only firewall cleanup.

From firewall access to identity exposure

FortiGate devices are valuable targets because they sit where many authentication flows converge. In enterprise environments, they may handle VPN access, directory lookups, database connections, email protocols, and remote administration traffic.

That position changes the impact of compromise. Once attackers gain administrative access, they can potentially collect authentication material from traffic passing through the device.

In the FortiBleed reporting, this shift matters for three reasons:

  • The exposure starts at the edge: CISA warned that leaked credentials were associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways.
  • The risk moves inward: SOCRadar’s expanded research says compromised FortiGate firewalls were reportedly used with custom sniffers to harvest authentication secrets.
  • The targeted data may go beyond firewall logins: FortigateSniffer reportedly targeted credentials and authentication artifacts across protocols such as Kerberos, LDAP, SMB, RADIUS, RDP, WinRM, SMTP, and database services.

This makes Fortinet credential theft more than a FortiGate administrator password problem. If a compromised firewall observed authentication traffic, the investigation should include the accounts, services, and endpoints connected to that traffic.

How FortigateSniffer reportedly worked

SOCRadar described FortigateSniffer as a custom Golang-based tool used after attackers gained administrative access to compromised FortiGate devices.

The tool reportedly connected over SSH and abused FortiOS’s built-in diagnostic sniffer packet capability to monitor authentication traffic.

The processing pipeline reconstructed the captured data into PCAP files, parsed them using a Python-based toolkit, and converted them into Hashcat-ready files for offline cracking.

SOCRadar said the tool targeted VPN credentials and authentication data across services such as Kerberos, LDAP, SMB, RADIUS, RDP, WinRM, SQL database, email, FTP, and Telnet protocols.

What the reported numbers actually mean

FortiBleed reporting includes several figures, but they do not measure the same thing. Some describe leaked Fortinet device credentials.

Others refer to scanned hosts, fingerprinted FortiGate devices, verified firewall credential records, or harvested authentication data.

Reported figure What it refers to Why it matters
430,000+ FortiGate firewalls targeted SOCRadar’s latest FortiBleed reporting Shows the campaign’s broad targeting scope
Approximately 19,000 devices with sniffers are reportedly deployed. SOCRadar’s latest update Indicates post-access packet capture at scale
Around 11,000 devices reportedly remained compromised after notification efforts. SOCRadar’s update after remediation efforts Suggests exposure declined but remained active
SOCRadar identified additional operational servers tied to the campaign. SOCRadar infrastructure analysis Shows supporting infrastructure beyond individual firewalls
Approximately 74,000 Fortinet devices CISA alert on leaked credentials Shows earlier credential exposure scale

These figures should not be merged into one claim. They describe separate layers of FortiBleed activity: scanning, fingerprinting, credential exposure, verified firewall access, and broader authentication harvesting.

For defenders, the takeaway is clear. Security teams should investigate FortiBleed as both an edge-device compromise risk and an identity exposure risk.

Why these credentials matter to ransomware operators

FortiBleed matters because the reported data is useful beyond firewall access. VPN credentials can support direct remote entry, while cracked hashes may expose reusable account passwords.

Service, email, database, and remote administration credentials can also open access to internal systems. Ransomware operators or access brokers may sell, reuse, or leverage that access to support later intrusion attempts.

This does not confirm ransomware deployment against every FortiBleed-affected organization. Security teams should treat exposed Fortinet and VPN credentials as potential ransomware precursor activity.

Where Hexnode fits after Edge-device exposure

This is not a FortiGate or ransomware attribution detection story for Hexnode. It is a post-exposure endpoint visibility and control problem.

When exposed credentials may lead to endpoint access, Hexnode UEM and Hexnode XDR can help teams strengthen managed device control and review endpoint activity within their supported scope.

Hexnode UEM can help teams:

  • Identify managed devices that may be used to access sensitive systems
  • Review compliance status across endpoints
  • Enforce policies on managed devices used by administrators
  • Maintain device inventory and update management across supported endpoints
  • Strengthen configuration control across managed endpoints

Hexnode XDR can help teams:

  • Review endpoint posture and agent status
  • Track endpoint incidents and security events
  • Investigate endpoint activity using telemetry
  • Verify policy rollouts, pending endpoint configurations, and deployment failures

For FortiBleed response, use Hexnode UEM and Hexnode XDR alongside firewall logs, VPN logs, identity telemetry, and network monitoring. The goal is to improve endpoint visibility and control after credential exposure, not to claim direct FortiBleed or ransomware attribution detection.

building a cybersecurity framework
Featured resource

Building a cybersecurity framework for your enterprise

Understand key cybersecurity frameworks and how UEM strengthens enterprise security, compliance, and risk control.

DOWNLOAD

Conclusion

The latest FortiBleed reporting shows how edge-device credential theft can become a ransomware access concern. The reported link to INC and Lynx does not confirm encryption or breach across every exposed FortiGate environment, but it should push security teams to prioritize credential rotation, firewall auditing, and identity review.

Security teams should identify exposed devices, check for persistent accounts, validate remaining credentials, and review whether attackers later used those credentials on endpoints or internal systems. Firewall hardening, credential rotation, identity log review, and endpoint visibility should move together.

FAQs

BleepingComputer reported that SOCRadar linked FortiBleed infrastructure to INC and Lynx ransomware operations. This does not confirm the ransomware impact for every affected organization.

No. Fortinet says its initial analysis points to credential reuse, weak authentication controls, prior exposure, and brute-force activity, not a new Fortinet vulnerability.

Start with FortiGate administrator and SSL VPN credentials, unknown accounts such as the reported adminin backdoor user, active sessions, configuration downloads, and authentication logs tied to VPN, identity, and remote access systems.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.