logo

FortiBleed Password Stealing Attack Linked to INC and Lynx Ransomware Operations

ID: 3266acd1-da30-5f72-9a03-8842c4786139

STIX ID: report--3266acd1-da30-5f72-9a03-8842c4786139

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-07-02

Date Updated: 2026-07-02

Author: Guru Baran

...
...

FortiBleed is a large-scale credential-harvesting campaign that has compromised FortiGate firewalls worldwide using a custom Golang "FortigateSniffer" to intercept authentication traffic; investigators linked the operation to roughly 430,000 targeted devices, confirmed admin-level access on hundreds of systems (409), full attack chains on 354 targets, and at least 12 confirmed ransomware deployments. Analysis of exposed infrastructure and internal documentation ties the harvested credentials to two active RaaS operations (INC Ransom and Lynx), indicating a structured initial-access brokerage operation that directly feeds ransomware economies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.