# FortiBleed: Ransomware Gangs Weaponize Thousands of Fortinet Firewall Compromises


A sophisticated attack campaign known as FortiBleed is emerging as a critical threat to enterprise security infrastructure. Threat actors have successfully compromised thousands of Fortinet FortiGate firewalls worldwide and are now actively monetizing that access by collaborating with established ransomware gangs, including the Inc and Lynx operations. The campaign compounds the threat by weaponizing a zero-day vulnerability in Nextcloud, expanding the attack surface beyond perimeter defenses into file-sharing and collaboration platforms.


## The Threat


FortiBleed represents a convergence of two dangerous trends in the threat landscape: mass compromise of critical security infrastructure and collaborative ransomware monetization. Security researchers have confirmed that thousands of Fortinet FortiGate firewalls—devices that serve as the primary security boundary for enterprise networks—have been compromised by FortiBleed operators.


What distinguishes this campaign from opportunistic attacks is the systematic monetization strategy. Rather than keeping compromises quiet, the threat actors are actively partnering with known ransomware gangs to leverage their firewall foothold into full network intrusions. This collaboration model suggests:


  • Shared intelligence networks between different threat actor groups
  • Specialization within cybercriminal operations (initial access brokers vs. encryption operators)
  • Scaling of ransomware attacks through reliable firewall-level compromise vectors

  • The addition of a Nextcloud zero-day to the attacker toolkit indicates that FortiBleed operators are not limited to single-vector attacks. They are combining multiple exploits to maximize their chances of successful network penetration and lateral movement.


    ## Technical Details: How FortiBleed Works


    ### Initial Compromise


    Fortinet firewalls are targeted through known vulnerabilities or misconfigurations that allow unauthenticated remote access. Once inside, attackers establish persistent backdoors that survive firmware updates and security patches, positioning them to monitor and intercept all traffic flowing through the firewall.


    From the firewall, the attack chain typically follows this progression:


    1. Reconnaissance: Attackers gain visibility into the internal network topology, security tools, and connected systems

    2. Lateral Movement: Using firewall access, they pivot to other critical infrastructure including domain controllers and file servers

    3. Secondary Exploitation: The Nextcloud zero-day is deployed when file-sharing or collaboration systems are discovered

    4. Handoff to Ransomware Partners: Once sufficient reconnaissance is complete, Inc or Lynx operators take over the compromise for encryption and extortion


    ### The Nextcloud Component


    The zero-day vulnerability in Nextcloud allows unauthenticated attackers to execute arbitrary code on Nextcloud instances. This is particularly dangerous because:


  • Common in enterprise environments: Nextcloud is widely deployed for document management and team collaboration
  • Trusted access: Firewall logs may not flag communications to internal Nextcloud servers as suspicious
  • Rich data access: Nextcloud instances typically contain sensitive files, contracts, and intellectual property
  • Backup of data exfiltration: Attackers can steal files before deploying ransomware, enabling double-extortion tactics

  • The combination of firewall compromise + Nextcloud zero-day creates a "kill chain" that can be executed automatically, reducing operator involvement and accelerating the time from compromise to ransomware deployment.


    ## Background and Context


    ### Why Firewalls Are Prized Targets


    Fortinet FortiGate devices are among the most widely deployed firewalls globally, protecting everything from small office networks to Fortune 500 datacenters. Control of a firewall grants attackers:


  • Complete visibility into all network traffic
  • Man-in-the-middle capabilities for intercepting credentials and session tokens
  • Network segmentation bypass to reach internal systems without triggering detection
  • Resilience — firewall access persists even after other compromises are discovered and remediated

  • This explains why initial access brokers (IABs) command premium prices for firewall credentials on darknet markets.


    ### The Ransomware Gang Ecosystem


    The Inc and Lynx ransomware operations are established players in the extortion economy:


  • Inc has been active since 2023, focusing on mid-market enterprises with annual revenues between $50M–$500M
  • Lynx emerged as a splinter group with similar operational capabilities and targeting patterns
  • Both groups maintain active data leak sites and have demonstrated willingness to follow through on extortion threats

  • The collaboration with FortiBleed operators suggests these groups have either:

  • Developed reliable relationships with access brokers
  • Pooled resources to acquire new compromise vectors
  • Standardized their attack infrastructure around specific entry points

  • ### Historical Precedent


    This is not the first time Fortinet firewalls have been targeted at scale. Previous campaigns including CVE-2018-13379 (Fortinet SSL-VPN credential disclosure) and CVE-2020-12812 (FortiGate authentication bypass) demonstrated that firewall vulnerabilities can be weaponized across millions of devices globally. However, FortiBleed appears to represent a more mature operational model, with built-in partnerships and multi-stage attack chains rather than simple credential theft.


    ## Monetization Strategy and Implications


    ### The Attack Economics


    The shift from passive network reconnaissance to active ransomware deployment reflects changing economics in the threat landscape:


    | Stage | Actor | Objective | Time to Value |

    |-------|-------|-----------|---------------|

    | Initial Compromise | FortiBleed operators | Establish foothold, build botnet | Days–weeks |

    | Reconnaissance | FortiBleed operators | Map network, identify valuables | Weeks–months |

    | Handoff | IAB-to-ransomware broker | Monetize access | Immediate |

    | Deployment | Inc/Lynx operators | Encrypt and extort | Hours |


    This model allows threat actors to specialize. FortiBleed operators focus on high-volume compromise and network understanding. Ransomware gangs focus on negotiation and payment collection—activities that benefit from operational security and reputation management.


    ### Double-Extortion at Scale


    By combining firewall access with the Nextcloud zero-day, attackers can:


    1. Exfiltrate sensitive data from shared drives and collaboration spaces

    2. Encrypt critical systems across the network

    3. Threaten to publish stolen files if ransom demands are not met

    4. Negotiate from a position of strength (data + service unavailability)


    Organizations facing double extortion pay higher ransoms on average, making this approach significantly more profitable than encryption-only attacks.


    ## What Organizations Should Do


    ### Immediate Actions


    Patch Fortinet FortiGate devices immediately. If zero-day or critical vulnerabilities exist without available patches, implement network segmentation to restrict access to firewall management interfaces.


    Audit Nextcloud instances for signs of compromise:

  • Review access logs for unauthenticated requests
  • Check for unusual file access or downloads
  • Scan for Web shells or persistent backdoors
  • Review recent file modifications and deletions

  • Enable enhanced logging on all firewalls and Nextcloud installations. This data will be critical for incident response if your organization is affected.


    ### Detection and Response


    Organizations should look for:


  • Unusual firewall admin logins from unfamiliar IP addresses, especially outside business hours
  • Suspicious Nextcloud API calls to non-existent endpoints or with unusual parameters
  • Lateral movement patterns consistent with post-compromise reconnaissance
  • Registry or configuration changes on systems reachable from the firewall

  • If a compromise is suspected, assume that attackers have:

  • Mapped your network topology
  • Identified high-value targets
  • Exfiltrated sensitive files
  • Positioned themselves for encryption

  • Do not simply patch and assume the threat is remediated. Assume persistence and conduct forensic analysis.


    ### Long-Term Resilience


  • Zero-trust architecture: Don't assume the firewall is the only defense
  • Network segmentation: Limit what systems are reachable from the firewall
  • Privileged access management: Restrict firewall admin credentials to highly secured jump servers
  • Immutable backups: Maintain offline backups that cannot be encrypted
  • Incident response planning: Establish runbooks for ransomware scenarios before you need them

  • ---


    ## HackWire Analysis


    FortiBleed marks an inflection point in how ransomware gangs operate. Rather than waiting for security researchers to discover new vulnerabilities, they are actively partnering with access brokers who maintain compromise infrastructure at scale. This professionalizes ransomware as a business.


    The pattern is worth noting: specialized attack phases with handoffs between actor groups. We've seen this with APT groups for years, but it's now native to the ransomware economy. Inc and Lynx don't need to build their own firewall exploit capabilities—they simply buy or barter for access from FortiBleed operators. This reduces their R&D costs and accelerates time-to-ransom.


    The Nextcloud zero-day addition is equally strategic. Nextcloud is ubiquitous in organizations trying to self-host their data to avoid cloud vendors. Attackers know that targeting these deployments yields high-confidence hits on sensitive, unencrypted data. By weaponizing Nextcloud alongside firewall access, FortiBleed operators can promise ransomware partners not just network access, but guaranteed data theft in the same attack package.


    The timing also matters. These partnerships typically emerge *after* a vulnerability has been known for weeks or months in the wild, but *before* enterprise patching is widespread. Organizations are in a window where they're vulnerable but unaware. That window is closing as news breaks, but it's likely already too late for many compromises already in motion.


    What defenders should assume: If your organization runs Fortinet FortiGate firewalls and Nextcloud, you are in the crosshairs of a professional, collaborative attack. This is not someone testing exploits for portfolio building. This is revenue-focused, with infrastructure and relationships to support rapid monetization.


    HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)