{"id":652,"date":"2026-07-03T15:56:19","date_gmt":"2026-07-03T10:26:19","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=652"},"modified":"2026-08-18T15:56:54","modified_gmt":"2026-08-18T10:26:54","slug":"fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/","title":{"rendered":"FortiBleed Credential Theft Linked to Lynx Ransomware Operations"},"content":{"rendered":"<p>Fortinet credential theft has moved from an edge-device exposure story to a ransomware access concern. BleepingComputer reported that SOCRadar linked the FortiBleed campaign to INC and Lynx ransomware operations, raising the risk that stolen Fortinet and <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-virtual-private-network-vpn\/\">VPN<\/a> credentials could support future network intrusions.<\/p>\n<p>BleepingComputer reported that SOCRadar linked the FortiBleed campaign to the INC and Lynx ransomware operations, raising concerns that stolen Fortinet and VPN credentials could enable subsequent intrusion attempts.<\/p>\n<p>Fortinet has said its initial analysis points to credential reuse and brute-force activity, not a new Fortinet vulnerability. The latest update does not change that distinction, but it adds a more serious operational concern: exposed edge-device credentials may become useful to <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-ransomware-in-cybersecurity\/\">ransomware<\/a> access pipelines.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tImprove credential theft detection with Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>What the Lynx Ransomware link changes<\/h2>\n<p>SOCRadar\u2019s latest FortiBleed reporting adds a ransomware access angle to the credential-theft campaign.<\/p>\n<h3>The update matters because:<\/h3>\n<ul>\n<li><strong>Ransomware infrastructure\u00a0<\/strong><strong>was identified in the investigation:<\/strong> According to BleepingComputer, SOCRadar linked the FortiBleed infrastructure to INC and Lynx ransomware operations.<\/li>\n<li><strong>The link came from campaign infrastructure:<\/strong> SOCRadar identified a Windows server used in the FortiBleed operation.<\/li>\n<li><strong>Ransomware panels were reportedly accessed:<\/strong> SOCRadar reported that browser sessions on that server accessed ransomware administration panels and negotiation dashboards containing victim chats.<\/li>\n<li><strong>The finding does not confirm ransomware impact for every victim:<\/strong> The reporting links infrastructure, not every affected FortiGate environment.<\/li>\n<li><strong>The response priority changes:<\/strong> Exposed Fortinet device and VPN credentials should be treated as possible initial access material, not only firewall cleanup.<\/li>\n<\/ul>\n<h2>From firewall access to identity exposure<\/h2>\n<p>FortiGate devices are valuable targets because they sit where many authentication flows converge. In enterprise environments, they may handle VPN access, directory lookups, database connections, email protocols, and remote administration traffic.<\/p>\n<p>That position changes the impact of compromise. Once attackers gain administrative access, they can potentially collect authentication material from traffic passing through the device.<\/p>\n<p>In the FortiBleed reporting, this shift matters for three reasons:<\/p>\n<ul>\n<li><strong>The exposure starts at the edge:<\/strong> CISA warned that leaked credentials were associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways.<\/li>\n<li><strong>The risk moves inward:<\/strong> SOCRadar\u2019s expanded research says compromised FortiGate firewalls were reportedly used with custom sniffers to harvest authentication secrets.<\/li>\n<li><strong>The targeted data may go beyond firewall logins:<\/strong> FortigateSniffer reportedly targeted credentials and authentication artifacts across protocols such as <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-kerberos\/\">Kerberos<\/a>, LDAP, SMB, RADIUS, RDP, WinRM, SMTP, and database services.<\/li>\n<\/ul>\n<p>This makes Fortinet credential theft more than a FortiGate administrator password problem. If a compromised firewall observed authentication traffic, the investigation should include the accounts, services, and endpoints connected to that traffic.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-challenges.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Cybersecurity Challenges for Enterprises<\/h4><p>Strengthen enterprise security with practical controls for today\u2019s biggest risks.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-10-cybersecurity-challenges-for-enterprises\/\" aria-label=\"Top 10 Cybersecurity Challenges for Enterprises\"><\/a><\/div><\/div><\/div>\n<h2>How FortigateSniffer reportedly worked<\/h2>\n<p>SOCRadar described FortigateSniffer as a custom Golang-based tool used after attackers gained administrative access to compromised FortiGate devices.<\/p>\n<p>The tool reportedly connected over SSH and abused FortiOS\u2019s built-in diagnostic sniffer packet capability to monitor authentication traffic.<\/p>\n<p>The processing pipeline reconstructed the captured data into PCAP files, parsed them using a Python-based toolkit, and converted them into Hashcat-ready files for offline cracking.<\/p>\n<p>SOCRadar said the tool targeted VPN credentials and authentication data across services such as Kerberos, LDAP, SMB, RADIUS, RDP, WinRM, SQL database, email, FTP, and Telnet protocols.<\/p>\n<h2>What the reported numbers actually mean<\/h2>\n<p>FortiBleed reporting includes several figures, but they do not measure the same thing. Some describe leaked Fortinet device credentials.<\/p>\n<p>Others refer to scanned hosts, fingerprinted FortiGate devices, verified firewall credential records, or harvested authentication data.<\/p>\n<table style=\"width: 100%; height: 216px;\">\n<thead>\n<tr style=\"height: 24px;\">\n<th style=\"width: 27.2727%; height: 24px; text-align: left;\">Reported figure<\/th>\n<th style=\"width: 35.7295%; height: 24px; text-align: left;\">What it refers to<\/th>\n<th style=\"width: 35.9407%; height: 24px; text-align: left;\">Why it matters<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 24px;\">\n<td style=\"width: 27.2727%; height: 24px;\">430,000+ FortiGate firewalls targeted<\/td>\n<td style=\"width: 35.7295%; height: 24px;\">SOCRadar\u2019s latest FortiBleed reporting<\/td>\n<td style=\"width: 35.9407%; height: 24px;\">Shows the campaign\u2019s broad targeting scope<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"width: 27.2727%; height: 48px;\">Approximately <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware\/utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=fortinet_credential_theft\" target=\"_blank\" rel=\"noopener\">19,000 devices<\/a> with sniffers are reportedly deployed.<\/td>\n<td style=\"width: 35.7295%; height: 48px;\">SOCRadar\u2019s latest update<\/td>\n<td style=\"width: 35.9407%; height: 48px;\">Indicates post-access packet capture at scale<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"width: 27.2727%; height: 48px;\">Around 11,000 devices reportedly remained compromised after notification efforts.<\/td>\n<td style=\"width: 35.7295%; height: 48px;\">SOCRadar\u2019s update after remediation efforts<\/td>\n<td style=\"width: 35.9407%; height: 48px;\">Suggests exposure declined but remained active<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"width: 27.2727%; height: 48px;\">SOCRadar identified additional operational servers tied to the campaign.<\/td>\n<td style=\"width: 35.7295%; height: 48px;\">SOCRadar infrastructure analysis<\/td>\n<td style=\"width: 35.9407%; height: 48px;\">Shows supporting infrastructure beyond individual firewalls<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 27.2727%; height: 24px;\">Approximately 74,000 Fortinet devices<\/td>\n<td style=\"width: 35.7295%; height: 24px;\">CISA alert on leaked credentials<\/td>\n<td style=\"width: 35.9407%; height: 24px;\">Shows earlier credential exposure scale<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>These figures should not be merged into one claim. They describe separate layers of FortiBleed activity: scanning, fingerprinting, credential exposure, verified firewall access, and broader authentication harvesting.<\/p>\n<p>For defenders, the takeaway is clear. Security teams should investigate FortiBleed as both an edge-device compromise risk and an identity exposure risk.<\/p>\n<h2>Why these credentials matter to ransomware operators<\/h2>\n<p>FortiBleed matters because the reported data is useful beyond firewall access. VPN credentials can support direct remote entry, while cracked hashes may expose reusable account passwords.<\/p>\n<p>Service, email, database, and remote administration credentials can also open access to internal systems. Ransomware operators or access brokers may sell, reuse, or leverage that access to support later intrusion attempts.<\/p>\n<p>This does not confirm ransomware deployment against every FortiBleed-affected organization. Security teams should treat exposed Fortinet and VPN credentials as potential ransomware precursor activity.<\/p>\n<h2>Where Hexnode fits after Edge-device exposure<\/h2>\n<p>This is not a FortiGate or ransomware attribution detection story for Hexnode. It is a post-exposure endpoint visibility and control problem.<\/p>\n<p>When exposed credentials may lead to endpoint access, Hexnode UEM and Hexnode XDR can help teams strengthen managed device control and review endpoint activity within their supported scope.<\/p>\n<h3>Hexnode UEM can help teams:<\/h3>\n<ul>\n<li>Identify managed devices that may be used to access sensitive systems<\/li>\n<li>Review compliance status across endpoints<\/li>\n<li>Enforce policies on managed devices used by administrators<\/li>\n<li>Maintain device inventory and update management across supported endpoints<\/li>\n<li>Strengthen configuration control across managed endpoints<\/li>\n<\/ul>\n<h3>Hexnode XDR can help teams:<\/h3>\n<ul>\n<li>Review endpoint posture and agent status<\/li>\n<li>Track endpoint incidents and security events<\/li>\n<li>Investigate endpoint activity using telemetry<\/li>\n<li>Verify policy rollouts, pending endpoint configurations, and deployment failures<\/li>\n<\/ul>\n<p>For FortiBleed response, use <a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> and <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-extended-detection-and-response-xdr\/\">Hexnode XDR<\/a> alongside firewall logs, VPN logs, identity telemetry, and network monitoring. The goal is to improve endpoint visibility and control after credential exposure, not to claim direct FortiBleed or ransomware attribution detection.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity framework\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity framework\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Building a cybersecurity framework for your enterprise\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Understand key cybersecurity frameworks and how UEM strengthens enterprise security, compliance, and risk control.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/building-a-cybersecurity-framework-for-your-enterprise\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Conclusion<\/h2>\n<p>The latest FortiBleed reporting shows how edge-device credential theft can become a ransomware access concern. The reported link to INC and Lynx does not confirm encryption or breach across every exposed FortiGate environment, but it should push security teams to prioritize credential rotation, firewall auditing, and identity review.<\/p>\n<p>Security teams should identify exposed devices, check for persistent accounts, validate remaining credentials, and review whether attackers later used those credentials on endpoints or internal systems. Firewall hardening, credential rotation, identity log review, and endpoint visibility should move together.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen control after credential exposure<\/h5><p>Start your 14-day free trial and improve endpoint control. <\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is FortiBleed linked to ransomware?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>BleepingComputer reported that SOCRadar linked FortiBleed infrastructure to INC and Lynx ransomware operations. This does not confirm the ransomware impact for every affected organization.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does this mean FortiBleed is a new Fortinet vulnerability?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Fortinet says its initial analysis points to credential reuse, weak authentication controls, prior exposure, and brute-force activity, not a new Fortinet vulnerability.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should organizations check first?\n<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Start with FortiGate administrator and SSL VPN credentials, unknown accounts such as the reported adminin backdoor user, active sessions, configuration downloads, and authentication logs tied to VPN, identity, and remote access systems.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Fortinet credential theft has moved from an edge-device exposure story to a ransomware access concern&#8230;.<\/p>\n","protected":false},"author":5,"featured_media":658,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,20],"class_list":["post-652","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-network-and-vpn","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Fortinet Credential Theft: FortiBleed Campaign<\/title>\n<meta name=\"description\" content=\"Fortinet credential theft campaign FortiBleed used FortigateSniffer to harvest VPN credentials, Kerberos hashes, and NTLM credentials.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fortinet Credential Theft: FortiBleed Campaign\" \/>\n<meta property=\"og:description\" content=\"Fortinet credential theft campaign FortiBleed used FortigateSniffer to harvest VPN credentials, Kerberos hashes, and NTLM credentials.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-03T10:26:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T10:26:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/fortinet-credential-theft.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"FortiBleed Credential Theft Linked to Lynx Ransomware Operations\",\"datePublished\":\"2026-07-03T10:26:19+00:00\",\"dateModified\":\"2026-08-18T10:26:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/\"},\"wordCount\":1218,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/fortinet-credential-theft.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Network and VPN\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/\",\"name\":\"Fortinet Credential Theft: FortiBleed Campaign\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/fortinet-credential-theft.jpeg?format=webp\",\"datePublished\":\"2026-07-03T10:26:19+00:00\",\"dateModified\":\"2026-08-18T10:26:54+00:00\",\"description\":\"Fortinet credential theft campaign FortiBleed used FortigateSniffer to harvest VPN credentials, Kerberos hashes, and NTLM credentials.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/fortinet-credential-theft.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/fortinet-credential-theft.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"fortinet credential theft\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FortiBleed Credential Theft Linked to Lynx Ransomware Operations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fortinet Credential Theft: FortiBleed Campaign","description":"Fortinet credential theft campaign FortiBleed used FortigateSniffer to harvest VPN credentials, Kerberos hashes, and NTLM credentials.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/","og_locale":"en_US","og_type":"article","og_title":"Fortinet Credential Theft: FortiBleed Campaign","og_description":"Fortinet credential theft campaign FortiBleed used FortigateSniffer to harvest VPN credentials, Kerberos hashes, and NTLM credentials.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-03T10:26:19+00:00","article_modified_time":"2026-08-18T10:26:54+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/fortinet-credential-theft.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"FortiBleed Credential Theft Linked to Lynx Ransomware Operations","datePublished":"2026-07-03T10:26:19+00:00","dateModified":"2026-08-18T10:26:54+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/"},"wordCount":1218,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/fortinet-credential-theft.jpeg?format=webp","articleSection":["Identity Abuse","Network and VPN"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/","url":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/","name":"Fortinet Credential Theft: FortiBleed Campaign","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/fortinet-credential-theft.jpeg?format=webp","datePublished":"2026-07-03T10:26:19+00:00","dateModified":"2026-08-18T10:26:54+00:00","description":"Fortinet credential theft campaign FortiBleed used FortigateSniffer to harvest VPN credentials, Kerberos hashes, and NTLM credentials.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/fortinet-credential-theft.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/fortinet-credential-theft.jpeg?format=webp","width":1340,"height":700,"caption":"fortinet credential theft"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/fortinet-credential-theft-fortibleed-turns-fortigate-firewalls-into-credential-harvesting-points\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"FortiBleed Credential Theft Linked to Lynx Ransomware Operations"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/652","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=652"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/652\/revisions"}],"predecessor-version":[{"id":659,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/652\/revisions\/659"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/658"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=652"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=652"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}