FortiBleed Credential Haul Now Feeding INC and Lynx Ransomware Crews

A single operator was spotted running negotiation panels for both gangs, turning stolen FortiGate logins into ransomware payloads.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a rack-mounted network security appliance in a dim server room, faint red status LEDs
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Investigators have linked the FortiBleed mass credential-theft campaign to INC and Lynx ransomware operations.
  • An operator tied to FortiBleed's infrastructure was found actively working victim negotiation panels for both groups.
  • INC and Lynx share tooling and negotiation infrastructure, reinforcing the view that Lynx is a fork or rebrand of INC.
  • Defenders should treat any FortiGate credential exposed during the FortiBleed window as compromised and rotate immediately.
  • The same individual appears to be stealing credentials and negotiating ransoms, collapsing what were once separate criminal roles.

What is FortiBleed and why does it matter now?

The FortiBleed campaign has a purpose, and it isn't resale on a forum. Investigators say harvested FortiGate logins are being funneled directly into ransomware intrusions run by the INC and Lynx crews. That attribution turns what looked like a generic credential-harvest into something more surgical: verified VPN and admin logins, pre-tested, handed to affiliates with a payload ready.

How did investigators connect FortiBleed to the ransomware groups?

The tell was operational, not technical. An operator tied to FortiBleed's infrastructure was found actively working negotiation panels for both INC and Lynx. That's unusual exposure: most credential brokers stay several hops away from the ransom conversation. This one didn't.

Should you worry about the INC and Lynx connection?

INC and Lynx have long looked like cousins. Lynx emerged in mid-2024 with tooling and negotiation infrastructure closely resembling INC's, and multiple trackers have treated it as either a rebrand or a fork. A shared credential pipeline, one operator on both panels, is another data point in that direction. It also suggests the two brands are sharing more than a codebase.

What should defenders do right now?

Treat any credential exposed during the FortiBleed window as compromised and rotate it now. The window between credential validation and ransomware deployment in these operations has historically been days, not months. Beyond rotation, audit VPN and admin session logs, then hunt for the usual INC and Lynx precursors: Rclone staging, AnyDesk installs outside sanctioned inventory, and abnormal SMB enumeration (a protocol used to share files across a network) from VPN-assigned IP ranges.

Two things are worth watching going forward. First, whether the FortiBleed infrastructure gets burned now that the link is public, or whether operators simply migrate hosts and continue. Prior campaigns tied ransomware affiliates to credential theft from network devices and showed surprising resilience. Second, whether Fortinet issues fresh guidance beyond a standard rotate-and-patch advisory.

What does this tell us about the broader threat landscape?

Credential theft as a service, ransomware as a service, and initial-access brokerage have been converging for years. Our June piece on infostealers as the front door for ransomware gangs made exactly this point. FortiBleed illustrates how thin the wall between those roles has become: the same person is stealing the keys and negotiating the ransom. Call it vertical integration for extortion.

The credentials are straightforward to fix. The dwell time already accumulated is what will hurt.

© 2026 Threat Vectr