FortiBleed is no longer just a credential-theft campaign. The stolen FortiGate access is being used as a handoff into ransomware operations, so the real exposure is both the firewall compromise and the extortion phase that follows.
SOCRadar tied an operator in the FortiBleed infrastructure to both INC and Lynx negotiation panels, and said that access has already led to at least 12 ransomware deployments. It also reported 409 admin-level compromises and 354 cases that reached the full attack chain, with hundreds of endpoints encrypted across affected organizations.
For teams that rely on edge-device credentials, the lesson is that stolen login data can become active intrusion capacity, not just a leaked secret. Patching the original firewall issue does not remove the downstream access already in circulation.