Visualização de leitura

430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link

FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks.

SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator with access to FortiBleed’s own infrastructure was found actively logged into the negotiation panels of both ransomware groups, handling ransom demands in real time.

FortiBleed has been documented since SOCRadar’s first report. The operation uses a custom tool written in Go called FortigateSniffer, which passively intercepts authentication traffic by abusing FortiOS’s own built-in packet diagnostic command across two dozen protocols.

The attacker never sends malicious payloads to the firewall. They just listen to the traffic the device generates itself. It’s a quiet way to collect credentials at scale, and it’s been running across more than 150 countries.

After the initial disclosure, SOCRadar continued mapping the campaign using Shodan, Censys, Validin, and its own scanning. That work turned up roughly 200 additional operational servers beyond the original dataset, a mix of credential sniffers and network scanners that hadn’t appeared in the first investigation. As the SOCRadar report states:

“Across the expanded infrastructure, STRU tracked scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets.” reads the report published by SocRadar. “On 354 of those, the actor completed the full attack chain: VPN compromise, access to the domain controller, and domain admin. STRU has confirmed at least 12 ransomware deployments stemming from this access, with hundreds of endpoints encrypted across affected organizations.”

That’s not credential theft sitting in a database waiting to be sold. That’s domain-level control of hundreds of organizations, obtained quietly through their own firewall. SOCRadar has confirmed at least 12 ransomware deployments traced directly to FortiBleed-derived access, with hundreds of endpoints encrypted across the affected organizations.

One of the newly discovered servers gave SOCRadar visibility into the group’s own internal environment. An operational security lapse in how the group managed its infrastructure exposed internal files, logs, and operational documentation. That’s what made the ransomware connection possible to prove rather than just infer.

Inside that environment, SOCRadar found an operator logged into negotiation panels for both INC Ransom and Lynx simultaneously.

INC Ransom has been active since mid-2023 and remains one of the more active ransomware-as-a-service operations by victim count. The INC RANSOM has claimed responsibility for the breach of at tens of organizations to date, including US hospice pharmacy  Xerox CorpOnePoint Patient Care, and Scotland’s National Health Service (NHS) Lynx appeared roughly a year later and is widely assessed as a direct evolution of INC. One operator, two brands, infrastructure traceable back to the credential harvesting campaign. The attribution case is direct.

SOCRadar also found a separately discovered open directory linked to INC Ransom and compared its contents against FortiBleed’s own target records. The victims matched.

“Comparing target and victim data from FortiBleed’s own infrastructure against a separately discovered INC-linked open directory, STRU found matching victims across both datasets, independent confirmation that the same organizations were being tracked by both the credential-harvesting operation and the ransomware group.” states SocRadar.

SOCRadar recovered an internal tracking document the group uses to manage its FortiGate targets, recording which credentials were used, which networks were accessed, and whether ransomware was eventually deployed. Analysis of this document points to a structured operation of roughly 20 people. A small core of primary operators handles the high-impact intrusions. Behind them sit dedicated specialists, and below those, a back-office layer of junior operators and technical support staff. It runs like a small company, with a division of labor that would look familiar on any org chart. (Except the product is ransomware.)

SOCRadar is withholding specific operator aliases, tooling details, and the full indicator set until the complete technical whitepaper publishes. That report will also cover a separate line of investigation into the group’s use of AI tools for vulnerability research, including work toward at least one undisclosed zero-day that SOCRadar is coordinating with the affected vendor through responsible disclosure.

The practical implication is direct.

This campaign isn’t an access broker quietly monetizing stolen credentials through underground markets at arm’s length from the actual attacks. The same infrastructure that collected the credentials is directly connected, through a shared operator, to the groups deploying ransomware on victim networks.

“The same access broker infrastructure that quietly intercepted authentication traffic across hundreds of thousands of firewalls is connected, through a shared operator, to two of the more active ransomware brands operating today.” concludes the report. “For organizations running FortiGate infrastructure, this raises the stakes on an already urgent finding: exposure to FortiBleed is not just a credential exposure risk, it is a potential precursor to ransomware.”

If your organization runs FortiGate infrastructure, the question isn’t whether your credentials were targeted. With 430,000 firewalls in scope and active scanning across 150 countries, the better question is whether your environment showed up in the 409 where admin access was confirmed, or the 354 where full domain compromise was achieved.

SOCRadar says the full indicator set will be in the forthcoming whitepaper. Watch for it.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations

Qilin

Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.

Qilin: The Dominant Force

Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking data, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count. Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of ransom proceeds. This model allows the core group to expand operational throughput without directly executing every attack. The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many healthcare organisations find more immediately damaging than operational downtime. A notable recent case involves Covenant Health, which suffered a Qilin ransomware breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.

INC Ransom: Targeting Critical Sectors

INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration. INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers. Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.

The 2026 Ransomware Landscape

Beyond Qilin and INC Ransom, the broader 2026 ransomware ecosystem is characterised by:
  • AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate phishing campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.
  • Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.
  • The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.

Why It Matters

The 30% year-over-year increase in ransomware incidents confirms that neither law enforcement action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated risk. For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural vulnerability that the industry has not yet resolved despite years of high-profile attacks.

March 2026 Ransomware Trends Report

Purpose and Scope. this report summarizes the number of ransomware samples, number of affected systems, DLS-based statistics, and major Korean & Global ransomware issues identified during the month of March 2026. Key statistics. ransomware sample counts and victimized systems statistics were aggregated by detection name assigned by AhnLab. statistics on targeted businesses were calculated based […]
❌