# FortiBleed: How Stolen Firewall Credentials Are Fueling Ransomware Operations at Scale


A sprawling credential-harvesting campaign targeting over 430,000 FortiGate firewalls globally has evolved into a direct pipeline feeding ransomware attacks against hundreds of organizations. Security researchers have now linked the FortiBleed operation to both INC Ransom and Lynx ransomware families, revealing how initial access brokers are weaponizing stolen network infrastructure to orchestrate high-impact extortion campaigns.


## The Threat: FortiBleed at Scale


FortiBleed, uncovered in mid-June 2026, represents one of the most ambitious infrastructure-targeting campaigns in recent memory. The operation has cast a net across 150 countries and compromised over 110 million credentials extracted from a diverse target set spanning thousands of organizations.


The attack surface is staggering:


| Metric | Count |

|--------|-------|

| FortiGate firewalls targeted | 430,000+ |

| FortiGate portals scanned | 11,250 |

| Targets with confirmed admin access | 409 |

| Organizations with full attack chain completion | 354 |

| Known ransomware deployment incidents | 12 |


The attackers leveraged a custom network sniffer dubbed FortigateSniffer deployed across compromised firewalls to capture cleartext credentials and password hashes transiting the devices. Because firewalls sit at the network perimeter and handle VPN traffic, they provide an ideal interception point for harvesting authentication data from multiple users and systems.


## Background and Context: The Ransomware Connection


The FortiBleed operation does not exist in isolation. Security researchers at SOCRadar confirmed that the same infrastructure and operators behind the credential-harvesting effort are directly connected to ransomware deployment campaigns.


INC Ransom, which emerged in mid-2023, has become one of the most prolific ransomware-as-a-service (RaaS) operations active today. The gang operates a typical RaaS model—developing the malware and infrastructure while recruiting affiliates to conduct intrusions and handle negotiations. Lynx, which appears to be an updated variant released roughly a year later, operates alongside INC in the same threat ecosystem.


The connection between FortiBleed and these ransomware families was not merely correlative. Researchers observed:


  • Shared operators: A single operator was logged into administrative panels for both INC Ransom and Lynx ransomware negotiations
  • Infrastructure overlap: Tracking infrastructure traced back to FortiBleed activities
  • Victim overlap: Organizations targeted in FortiBleed operations were subsequently targeted by INC Ransom attackers
  • Timeline alignment: The credentialing campaign directly precedes ransomware deployment against the same targets

  • This represents a formalized supply chain within the ransomware ecosystem—initial access brokers (IABs) harvesting credentials at scale, then either selling that access or using it directly to conduct extortion operations.


    ## Technical Details: How FortiBleed Works


    The attack chain reveals sophistication in both execution and persistence:


    Stage 1: Discovery and Reconnaissance

    Attackers scanned approximately 11,250 exposed FortiGate management interfaces across the internet. Organizations that failed to restrict administrative access to authorized IP ranges or enforce strong authentication became visible targets.


    Stage 2: Initial Compromise

    Through credential stuffing, weak credentials, or exploitation of known vulnerabilities, attackers gained administrative access to 409 FortiGate appliances. Once inside the device, they deployed FortigateSniffer.


    Stage 3: Credential Harvesting

    The sniffer intercepted traffic traversing the firewall, including:

  • VPN authentication credentials
  • Active Directory authentication traffic
  • Session tokens and API credentials
  • Plaintext passwords in legacy protocols

  • Because firewalls handle encrypted VPN traffic, attackers could capture credentials before encryption occurred on the inbound side, and after decryption on the outbound side.


    Stage 4: Post-Exploitation

    In 354 organizations, attackers completed the full kill chain:

  • Compromised VPN infrastructure
  • Accessed domain controllers
  • Escalated to domain administrator privileges
  • Established persistent backdoor access

  • Stage 5: Ransomware Deployment

    In at least 12 of these cases, attackers deployed ransomware families (INC Ransom and Lynx), encrypting hundreds of endpoints and initiating extortion negotiations.


    ## Investigation and Attribution: How Researchers Gained Visibility


    SOCRadar's breakthrough came through an operational security error by the attackers. An exposed logging or staging environment provided researchers with access to:


  • Internal files and documentation
  • Operational logs
  • Shared accounts and credentials
  • Tracking databases

  • Analysis of FortiBleed's internal tracking documents suggested the operation involves approximately 20 individuals, with defined roles:

  • Some operators focused on high-impact intrusions and ransomware deployment
  • Others provided technical support and credential management
  • Infrastructure specialists maintained the sniffer and command-and-control network

  • The presence of a single operator authenticated to both INC Ransom and Lynx negotiation panels—and the infrastructure overlap between FortiBleed and those panels—provided "the clearest evidence yet that FortiGate credentials harvested through this campaign are being handed off, or used directly, for ransomware deployment," according to SOCRadar's analysis.


    Attribution factors pointing to Russian actors:

  • Infrastructure hosted in Russian ASNs
  • Operational hours consistent with Eastern European time zones
  • Targeting patterns aligned with known Russian-linked threat groups
  • The professional coordination and scale suggest state-adjacent actors or well-established IAB networks

  • ## Implications: Who Is at Risk?


    Organizations running FortiGate appliances face immediate risk, particularly if:


  • Management interfaces are internet-exposed without strict IP allowlisting
  • Weak or default credentials remain in use on administrative accounts
  • VPN authentication relies on legacy protocols (RADIUS, TACACS) without encryption
  • No network detection or intrusion detection monitors firewall admin access
  • Active Directory relies on NTLM for authentication (vulnerable to relay attacks)

  • The impact extends beyond the 12 confirmed ransomware deployments. Organizations with harvested credentials face:


  • Post-breach access: Attackers retain domain admin privileges even after initial remediaton
  • Lateral movement: Stolen credentials enable access to on-premises systems, cloud environments (M365, AWS), and application servers
  • Supply chain risk: Compromised domains can be used to distribute malware or conduct further attacks against partners
  • Regulatory exposure: Breaches involving infrastructure compromise may trigger notification obligations under data protection laws

  • ## Recommendations: Defensive Actions


    Immediate (24-48 hours):

  • Audit FortiGate firewall management interface accessibility—restrict access to known administrative IP ranges
  • Reset all administrative credentials on FortiGate devices
  • Review VPN access logs for anomalous authentication patterns
  • Check Active Directory logs for suspicious domain admin account activity
  • Scan for FortigateSniffer and similar unauthorized modules on firewalls

  • Short-term (1-2 weeks):

  • Enable multi-factor authentication (MFA) on all firewall administrative accounts
  • Migrate VPN authentication from NTLM to more secure methods (Kerberos, certificate-based)
  • Implement network segmentation to limit lateral movement if firewall credentials are compromised
  • Deploy endpoint detection and response (EDR) to detect ransomware execution
  • Review and update firewall firmware to the latest patch level

  • Long-term:

  • Implement zero-trust architecture to reduce reliance on perimeter device credentials
  • Deploy DNS filtering and external network monitoring to detect C2 communication
  • Conduct regular penetration testing of firewall configurations and access controls
  • Establish incident response procedures specifically for infrastructure compromise scenarios

  • ## HackWire Analysis


    FortiBleed exposes a critical gap in how organizations think about infrastructure security. Firewalls are often treated as static defensive perimeters rather than high-value targets worthy of the same credential hygiene and monitoring applied to domain controllers and identity systems. Yet firewalls sit at the network's most privileged vantage point—able to intercept authentication traffic before encryption, inspect outbound data exfiltration, and pivot directly to core infrastructure.


    What distinguishes FortiBleed from previous campaigns is the industrialization of the IAB-to-ransomware supply chain. Researchers have previously observed scattered connections between access brokers and ransomware gangs, but the FortiBleed operation reveals a formalized pipeline: 20-person operation, internal tracking databases, shared operator infrastructure, and direct credential handoff to commodity ransomware-as-a-service platforms. This pattern likely repeats across other infrastructure-targeting campaigns. The operation wasn't trying to exploit zero-days or conduct sophisticated social engineering—it simply accepted that hundreds of thousands of organizations would leave firewall management interfaces internet-accessible and accept weak credentials.


    The timing also matters. As organizations harden perimeter defenses against ransomware, attackers are doubling down on infrastructure compromise as the initial foothold. FortiBleed demonstrates that if you control the firewall, you control the audit trail, the VPN gateway, and the credentials flowing through the network. For defenders, this means infrastructure security is no longer a hygiene issue—it's a ransomware prevention imperative.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)