FortiBleed is no longer just a credential-theft campaign. The stolen FortiGate access is being used as a handoff into ransomware operations, so the real exposure is both the firewall compromise and the extortion phase that follows.
SOCRadar tied an operator in the FortiBleed infrastructure to both INC and Lynx negotiation panels, and said that access has already led to at least 12 ransomware deployments. It also reported 409 admin-level compromises and 354 cases that reached the full attack chain, with hundreds of endpoints encrypted across affected organizations.
For teams that rely on edge-device credentials, the lesson is that stolen login data can become active intrusion capacity, not just a leaked secret. Patching the original firewall issue does not remove the downstream access already in circulation.
CVSS 9.8 CRITICAL: a improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated… EPSS 89% (100th percentile).
After gaining a foothold in 1000s of Fortinet firewalls, attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug.
Researchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations.
The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions.