FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
Reported exploitedFortiGateOur summary
The FortiBleed campaign, which focuses on harvesting credentials from exposed Fortinet FortiGate systems, has been linked by SOCRadar to INC and Lynx ransomware operations—suggesting stolen logins were used for follow-on intrusions. The activity involved probing roughly 11,250 FortiGate portals, gaining admin access on 409 targets, and completing the attack chain on 354, leading to at least 12 ransomware deployments and widespread endpoint encryption. Separately, eSentire reported active exploitation of Fortinet FortiClient EMS vulnerabilities tied to CVE-2026-35616 (CVSS 9.1), enabling deployment of EKZ Stealer to harvest browser credentials.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.