Post
CRITICAL ⚡ MUST-KNOW

FortiBleed Credential Theft Tied to INC and Lynx Ransomware Operations

· fortinet · ransomware · vulnerability

The FortiBleed campaign, which harvested credentials from hundreds of thousands of FortiGate firewalls, has been attributed to the INC and Lynx ransomware operations. Researchers found an operator tied to FortiBleed’s infrastructure actively working negotiation panels for both groups, linking mass FortiGate credential theft directly to follow-on ransomware deployment. Given the scale of harvested credentials, organizations running affected FortiGate appliances should assume compromise and rotate credentials rather than wait for a breach notification.