FortiBleed identified as the initial access vector for INC and Lynx ransomware operations
- Evelyn Carter

- Jul 7
- 3 min read
A new report from SOCRadar confirms that the FortiBleed campaign has resulted in 409 compromised FortiGate administrator accounts, 354 successful intrusions, and at least 12 confirmed ransomware incidents. This marks the first time technical evidence has directly linked FortiBleed to the ransomware operations of the INC and Lynx groups.
The findings represent the first confirmed connection between FortiBleed and ransomware campaigns based on forensic evidence collected from the threat actor's own infrastructure.
What did SOCRadar discover about the connection between FortiBleed and ransomware?
During its investigation into the infrastructure behind the FortiBleed campaign, SOCRadar researchers identified a Windows server used by the threat actor.
Log files, internal documents, and forensic data recovered from the server revealed that the same threat actor had accessed the ransomware negotiation panels of both INC and Lynx. In addition, SOCRadar found overlaps between organizations compromised through FortiBleed and victims that later appeared on the ransomware leak sites, further strengthening the connection between the credential theft campaign and subsequent ransomware attacks.

How large is the FortiBleed campaign?
According to the report, threat actors scanned approximately 11,250 FortiGate endpoints across more than 150 countries in search of vulnerable systems.
The investigation identified:
Approximately 409 compromised administrator accounts
354 successful intrusions completing the full attack chain
At least 12 confirmed ransomware deployments
Hundreds of organizational endpoints encrypted after attackers gained unauthorized access
These figures indicate that the campaign evolved beyond simple credential theft, with stolen access being actively leveraged to deploy ransomware.
How does FortiBleed operate?
SOCRadar reported that the campaign primarily targets Internet-exposed FortiGate devices.
After obtaining administrative privileges, the attackers collect additional credentials, expand their access within the victim's environment, and maintain persistence across compromised infrastructure. The stolen access is then used either to execute the complete attack chain or to facilitate ransomware deployment.
Based on its operational behavior, SOCRadar believes the actors behind FortiBleed exhibit the characteristics of an Initial Access Broker (IAB) - a threat actor specializing in obtaining and maintaining initial access to victim networks before either exploiting that access directly or supplying it to ransomware operators.

What should organizations using FortiGate do?
As the campaign remains under active monitoring, SOCRadar recommends that organizations using FortiGate appliances proactively assess their environments for signs of compromise.
Recommended actions include:
Reviewing all administrator accounts on FortiGate devices
Resetting passwords and credentials if exposure is suspected
Monitoring for suspicious login attempts and administrative activities
Investigating unauthorized accounts or persistence mechanisms within the environment
Why do these findings matter?
Previously, FortiBleed was primarily known as a credential theft campaign targeting FortiGate devices. However, SOCRadar's latest findings demonstrate that the stolen credentials were subsequently used as the initial access point for ransomware operations conducted by INC and Lynx.
The report highlights that compromised credentials are no longer just an account security issue—they can become a critical link in the entire cyberattack lifecycle. Organizations relying on FortiGate should prioritize reviewing privileged access, rotating potentially exposed credentials, and monitoring for abnormal authentication activities to reduce the risk of exploitation.
Protecting Your Organization's Digital Defense
To strengthen cybersecurity resilience against increasingly sophisticated targeted attacks, IPSIP Vietnam provides comprehensive cybersecurity solutions, professional security monitoring services, and rapid incident response capabilities that help organizations protect their critical infrastructure and maintain business continuity.

IPSIP Vietnam's management and monitoring platform has successfully passed rigorous independent assessments to achieve internationally recognized ISO/IEC 27001:2022 and SOC 2 Type II certifications. Through its 24/7 Security Operations Center (SOC), 24/7 Network Operations Center (NOC), and dedicated IT Support/Helpdesk teams, IPSIP delivers continuous monitoring, rapid threat detection, and around-the-clock incident response to help organizations defend against cyber threats at any time.
References









Comments