logo

FortiBleed Campaign Linked to INC and Lynx Ransomware Operations

ID: 66cba35f-fd62-57e8-b524-15d2abd9cfd3

STIX ID: report--66cba35f-fd62-57e8-b524-15d2abd9cfd3

Feed Name: GBHackers

Threat Score
86/100

Date Published: 2026-07-02

Date Updated: 2026-07-21

Author: Divya

...
...

Researchers uncovered that the FortiBleed campaign used a custom Golang tool to harvest FortiGate credentials from hundreds of thousands of devices, leading to administrative access in hundreds of cases and full compromises in dozens; evidence from exposed operator infrastructure links these stolen credentials directly to ransomware-as-a-service groups INC Ransom and Lynx, confirming that firewall credential theft is being integrated into ransomware deployment workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.