FortiBleed’s Bill Comes Due: 430,000 Leaked Fortinet Devices Now Feeding INC and Lynx Ransomware

The other shoe has dropped on FortiBleed. The mass credential-theft campaign that scraped logins from more than 430,000 Fortinet devices was never going to end with the credentials sitting in a folder, and now researchers say those credentials are feeding two active ransomware operations.

According to reporting from BleepingComputer, threat intelligence firm SOCRadar has tied the FortiBleed campaign directly to the INC Ransom and Lynx ransomware groups. Investigators reportedly found a server connected to FortiBleed’s infrastructure that had been used to access the negotiation panels for both ransomware operations, along with victim data that overlapped with organizations later named on INC’s leak site. Researchers estimate the operation involved roughly 20 people and deployed traffic-sniffing tools on close to 19,000 FortiGate devices.

From credential harvest to ransomware pipeline

This is the part of the story that security teams keep learning the hard way: stolen edge-device credentials are not a low-severity problem you can file under “rotate eventually.” A VPN or firewall login is initial access, and initial access is the single most valuable thing a ransomware crew buys. When a campaign harvests credentials at the scale of hundreds of thousands of devices and then hands them to groups that run extortion operations end to end, the distance between “a device leaked a credential” and “the company is on a leak site” collapses to almost nothing.

The overlap SOCRadar describes — shared infrastructure touching both groups’ negotiation panels, victim lists that line up with INC’s leak site — is the kind of connective tissue that turns a vague “credentials were stolen” into a concrete supply chain from harvest to encryption. We’ll note these are researchers’ assessments rather than a courtroom finding, but the picture is coherent and it is not comforting.

What to do about it

  • Assume exposure: If your FortiGate or other Fortinet appliances were internet-facing during the FortiBleed window, treat their credentials as compromised, full stop.
  • Rotate everything the device touched: Reset local and VPN credentials, invalidate active sessions, and rotate any shared secrets or service accounts that lived on or authenticated through the appliance.
  • Patch and update the appliances themselves: Bring Fortinet devices to current firmware and confirm you actually applied the fixes for previously disclosed FortiGate flaws.
  • Enforce MFA at the edge: A stolen password should not be a complete key; require strong multi-factor authentication on VPN and remote access.
  • Hunt for post-access activity: Look for lateral movement, new privileged accounts, and the reconnaissance that precedes ransomware — the credential theft may be old news, but the intrusion it enabled might be current.

The outrage

Edge devices were supposed to be the moat. Increasingly, they are the drawbridge someone left down. Firewalls and VPN concentrators sit at the perimeter precisely because they are trusted, which is exactly what makes a credential leak from one so devastating: the thing guarding the door hands out the keys. FortiBleed is a case study in why “it’s just a firewall bug” is a sentence that should make a CISO flinch.

And here we are, watching a bulk credential harvest mature into a two-ransomware-group feeder operation, exactly as anyone paying attention predicted. The credentials are out. The only variable left is how quickly defenders rotate, hunt, and lock down before INC and Lynx work through the list. Move faster than the leak site.

Leave a Reply

Discover more from Cyber Outrage

Subscribe now to keep reading and get access to the full archive.

Continue reading