# FortiBleed: Ransomware Gangs Weaponize Thousands of Fortinet Firewall Compromises
A sophisticated attack campaign known as FortiBleed is emerging as a critical threat to enterprise security infrastructure. Threat actors have successfully compromised thousands of Fortinet FortiGate firewalls worldwide and are now actively monetizing that access by collaborating with established ransomware gangs, including the Inc and Lynx operations. The campaign compounds the threat by weaponizing a zero-day vulnerability in Nextcloud, expanding the attack surface beyond perimeter defenses into file-sharing and collaboration platforms.
## The Threat
FortiBleed represents a convergence of two dangerous trends in the threat landscape: mass compromise of critical security infrastructure and collaborative ransomware monetization. Security researchers have confirmed that thousands of Fortinet FortiGate firewalls—devices that serve as the primary security boundary for enterprise networks—have been compromised by FortiBleed operators.
What distinguishes this campaign from opportunistic attacks is the systematic monetization strategy. Rather than keeping compromises quiet, the threat actors are actively partnering with known ransomware gangs to leverage their firewall foothold into full network intrusions. This collaboration model suggests:
The addition of a Nextcloud zero-day to the attacker toolkit indicates that FortiBleed operators are not limited to single-vector attacks. They are combining multiple exploits to maximize their chances of successful network penetration and lateral movement.
## Technical Details: How FortiBleed Works
### Initial Compromise
Fortinet firewalls are targeted through known vulnerabilities or misconfigurations that allow unauthenticated remote access. Once inside, attackers establish persistent backdoors that survive firmware updates and security patches, positioning them to monitor and intercept all traffic flowing through the firewall.
From the firewall, the attack chain typically follows this progression:
1. Reconnaissance: Attackers gain visibility into the internal network topology, security tools, and connected systems
2. Lateral Movement: Using firewall access, they pivot to other critical infrastructure including domain controllers and file servers
3. Secondary Exploitation: The Nextcloud zero-day is deployed when file-sharing or collaboration systems are discovered
4. Handoff to Ransomware Partners: Once sufficient reconnaissance is complete, Inc or Lynx operators take over the compromise for encryption and extortion
### The Nextcloud Component
The zero-day vulnerability in Nextcloud allows unauthenticated attackers to execute arbitrary code on Nextcloud instances. This is particularly dangerous because:
The combination of firewall compromise + Nextcloud zero-day creates a "kill chain" that can be executed automatically, reducing operator involvement and accelerating the time from compromise to ransomware deployment.
## Background and Context
### Why Firewalls Are Prized Targets
Fortinet FortiGate devices are among the most widely deployed firewalls globally, protecting everything from small office networks to Fortune 500 datacenters. Control of a firewall grants attackers:
This explains why initial access brokers (IABs) command premium prices for firewall credentials on darknet markets.
### The Ransomware Gang Ecosystem
The Inc and Lynx ransomware operations are established players in the extortion economy:
The collaboration with FortiBleed operators suggests these groups have either:
### Historical Precedent
This is not the first time Fortinet firewalls have been targeted at scale. Previous campaigns including CVE-2018-13379 (Fortinet SSL-VPN credential disclosure) and CVE-2020-12812 (FortiGate authentication bypass) demonstrated that firewall vulnerabilities can be weaponized across millions of devices globally. However, FortiBleed appears to represent a more mature operational model, with built-in partnerships and multi-stage attack chains rather than simple credential theft.
## Monetization Strategy and Implications
### The Attack Economics
The shift from passive network reconnaissance to active ransomware deployment reflects changing economics in the threat landscape:
| Stage | Actor | Objective | Time to Value |
|-------|-------|-----------|---------------|
| Initial Compromise | FortiBleed operators | Establish foothold, build botnet | Days–weeks |
| Reconnaissance | FortiBleed operators | Map network, identify valuables | Weeks–months |
| Handoff | IAB-to-ransomware broker | Monetize access | Immediate |
| Deployment | Inc/Lynx operators | Encrypt and extort | Hours |
This model allows threat actors to specialize. FortiBleed operators focus on high-volume compromise and network understanding. Ransomware gangs focus on negotiation and payment collection—activities that benefit from operational security and reputation management.
### Double-Extortion at Scale
By combining firewall access with the Nextcloud zero-day, attackers can:
1. Exfiltrate sensitive data from shared drives and collaboration spaces
2. Encrypt critical systems across the network
3. Threaten to publish stolen files if ransom demands are not met
4. Negotiate from a position of strength (data + service unavailability)
Organizations facing double extortion pay higher ransoms on average, making this approach significantly more profitable than encryption-only attacks.
## What Organizations Should Do
### Immediate Actions
Patch Fortinet FortiGate devices immediately. If zero-day or critical vulnerabilities exist without available patches, implement network segmentation to restrict access to firewall management interfaces.
Audit Nextcloud instances for signs of compromise:
Enable enhanced logging on all firewalls and Nextcloud installations. This data will be critical for incident response if your organization is affected.
### Detection and Response
Organizations should look for:
If a compromise is suspected, assume that attackers have:
Do not simply patch and assume the threat is remediated. Assume persistence and conduct forensic analysis.
### Long-Term Resilience
---
## HackWire Analysis
FortiBleed marks an inflection point in how ransomware gangs operate. Rather than waiting for security researchers to discover new vulnerabilities, they are actively partnering with access brokers who maintain compromise infrastructure at scale. This professionalizes ransomware as a business.
The pattern is worth noting: specialized attack phases with handoffs between actor groups. We've seen this with APT groups for years, but it's now native to the ransomware economy. Inc and Lynx don't need to build their own firewall exploit capabilities—they simply buy or barter for access from FortiBleed operators. This reduces their R&D costs and accelerates time-to-ransom.
The Nextcloud zero-day addition is equally strategic. Nextcloud is ubiquitous in organizations trying to self-host their data to avoid cloud vendors. Attackers know that targeting these deployments yields high-confidence hits on sensitive, unencrypted data. By weaponizing Nextcloud alongside firewall access, FortiBleed operators can promise ransomware partners not just network access, but guaranteed data theft in the same attack package.
The timing also matters. These partnerships typically emerge *after* a vulnerability has been known for weeks or months in the wild, but *before* enterprise patching is widespread. Organizations are in a window where they're vulnerable but unaware. That window is closing as news breaks, but it's likely already too late for many compromises already in motion.
What defenders should assume: If your organization runs Fortinet FortiGate firewalls and Nextcloud, you are in the crosshairs of a professional, collaborative attack. This is not someone testing exploits for portfolio building. This is revenue-focused, with infrastructure and relationships to support rapid monetization.
— HackWire Editorial
---
## Related Coverage