FortiBleed, the large-scale campaign targeting Fortinet FortiGate firewalls and VPN gateways, has now been linked to the ransomware groups INC and Lynx, making the threat even more serious. Security researchers found evidence that the stolen credentials are not only being collected but are also being used in real ransomware operations. This marks one of the clearest connections between the FortiBleed campaign and ransomware deployment. The findings highlight how stolen network credentials can quickly become the starting point for much larger cyberattacks.

According to researchers, the FortiBleed campaign did not rely on a newly discovered Fortinet vulnerability. Instead, attackers took advantage of weak passwords, reused credentials from older security incidents, credential stuffing, password spraying, and brute-force attacks against internet-facing Fortinet devices. Security experts also confirmed that many organizations had not enabled multi-factor authentication, making it easier for attackers to gain access using valid usernames and passwords. Fortinet has stated that this activity is not the result of a new software flaw but is mainly caused by poor credential security and previously compromised accounts.
Investigators discovered that the operators behind the FortiBleed infrastructure were actively managing negotiation panels associated with both the INC and Lynx ransomware-as-a-service operations. This discovery strongly suggests that the same threat actors collecting Fortinet credentials are also involved in launching ransomware attacks against compromised organizations. Researchers believe this is the first time the credential-harvesting campaign has been directly connected to active ransomware deployment. The link significantly increases the overall risk for organizations whose Fortinet credentials may have been exposed.

The campaign has affected organizations across 194 countries and spans multiple industries, including telecommunications, government, healthcare, finance, education, manufacturing, and critical infrastructure. Researchers identified tens of thousands of compromised or exposed Fortinet devices, with many of them still accessible through the internet. Attackers reportedly built a large database of verified working credentials that could be reused to gain unauthorized access to corporate networks. Countries with high numbers of affected systems include India, the United States, and several other regions with widespread Fortinet deployments.
Security researchers explained that the attackers first searched for internet-exposed Fortinet management interfaces and SSL VPN gateways. They then combined credentials collected from previous data leaks with automated password-guessing techniques to identify working accounts. In some cases, compromised devices were reportedly used to monitor network traffic and capture additional credentials, allowing the attackers to expand their access inside victim environments. This approach helped them move beyond a single compromised device and reach other systems connected to the same network.

Fortinet has responded by saying it is actively investigating the campaign and has started contacting customers whose systems may have been affected. The company emphasized that organizations should not treat this incident as a new vulnerability but instead focus on securing existing credentials and strengthening authentication. Fortinet also reminded customers to follow earlier security advisories, complete all recommended remediation steps, and review any previous incidents involving compromised accounts. The company is working with government agencies as part of its ongoing investigation.
Cybersecurity experts recommend that organizations immediately reset all administrator and VPN passwords, especially if the same credentials have been reused elsewhere. They also advise enabling multi-factor authentication for every administrative account, limiting public access to management interfaces, reviewing authentication logs for suspicious activity, and updating Fortinet devices to supported software versions. Even fully patched systems should be checked because valid stolen credentials can still provide attackers with access if passwords have not been changed. Organizations should also assume compromise if there are signs of unauthorized login activity.

The FortiBleed campaign demonstrates that stolen credentials can be just as dangerous as software vulnerabilities. Instead of exploiting a new security flaw, attackers relied on weak password practices and previously exposed credentials to infiltrate networks and prepare ransomware attacks. The newly discovered connection with the INC and Lynx ransomware groups shows how credential theft can directly lead to business disruption, data encryption, and financial extortion. For organizations using Fortinet products, strengthening credential security and monitoring for suspicious access have become essential steps in reducing the risk of future attacks.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news