GoFirm
Back to Blog
Case Studies·4 min read

The exposed staging server that connected 110 million stolen firewall credentials to two ransomware gangs

By GoFirm

Researchers at SOCRadar have linked a mass credential harvesting campaign called FortiBleed directly to ransomware deployment for the first time. Attackers scanned 430,000 Fortinet FortiGate firewalls, harvested more than 110 million credentials, and handed verified access to the INC Ransom and Lynx ransomware operations. At least twelve ransomware deployments followed, encrypting hundreds of endpoints across affected organisations. The link was only discovered because the attackers made a mistake.

Published on 14 July 2026

In February 2026, a Russian speaking initial access broker began a campaign researchers have named FortiBleed, systematically scanning the internet for Fortinet FortiGate firewalls. By July 2026 the operation had targeted more than 430,000 devices worldwide. The attackers used tools including Masscan and Shodan for reconnaissance, then a custom credential checker named forticheck to brute force and credential stuff their way into FortiGate administrative panels and SSL-VPN portals. Confirmed admin level access followed on 409 of roughly 11,250 targeted portals scanned across more than 150 countries, with the full attack chain completed on 354 of them.

Access alone was not the objective. Once inside, the attackers deployed a Golang based tool called FortigateSniffer, which abused a native FortiOS diagnostic command to passively intercept authentication traffic across 24 protocols, from Kerberos and LDAP to RDP and MySQL. The captured password hashes were cracked using Hashmat and Hashtopolis, orchestrated through a Telegram bot named HASHBOT, then reused against Active Directory domains and other exposed services. By the time the campaign was mapped, the attackers had harvested more than 110 million credentials, including 14.8 million RADIUS credentials, 924,000 NTLM hashes, and 89 million MySQL authentication tokens. The sniffer had been installed on around 12,000 of the compromised devices.

The scale of the operation only became visible because the attackers left a staging and coordination server exposed on the internet, giving researchers access to target inventories, harvested data, automation scripts and internal documentation. That exposure revealed something the industry had not previously confirmed: an operator with access to FortiBleed's infrastructure was logged into the negotiation panels of two ransomware operations, INC Ransom and Lynx, and victims listed by INC Ransom overlapped with FortiBleed's own data. At least twelve ransomware deployments have now been tied to the campaign, encrypting hundreds of endpoints across the affected organisations. The operation is believed to involve around twenty people, with a small core of lead operators supported by specialists and back office staff, targeting manufacturing, technology and logistics firms concentrated in Latin America and Asia Pacific.

This is the pattern behind a growing share of 2026's ransomware losses. Initial access brokers harvest credentials at industrial scale, then sell or hand that access to ransomware operators who never need to breach a perimeter themselves, because the perimeter was already opened by someone else weeks earlier. The FortiBleed operators are already reconnoitring beyond Fortinet, with a target list covering roughly 29,000 IP addresses and 37 domains associated with Citrix SSL-VPN environments, and they are believed to hold at least one unpatched zero-day vulnerability in Nextcloud. The credential economy that fuels ransomware is not slowing down. It is diversifying.

The defences that failed here were not weak by conventional standards. Fortinet firewalls sit at the perimeter precisely to stop this kind of intrusion, and the organisations affected had invested in the hardware the industry recommends. None of it addressed the moment that mattered: a verified administrative credential, harvested from network traffic weeks earlier, being used to log into a VPN or deploy ransomware across an estate. At that moment, the credential was valid. Nothing asked whether the login was authorised by anyone.

A VPN login using verified administrative credentials, or a command that begins encrypting production systems, is an execution event. Before either can proceed from an unrecognised context, GoFirm sends a real time confirmation request to the named authority responsible for that system, delivered to their registered device, requiring biometric confirmation before the session opens or the deployment runs. No confirmation, no execution.

An initial access broker holding a verified credential, however cleanly harvested, cannot produce a biometric confirmation on the named authority's registered device through a separate channel. The execution boundary holds regardless of how valid the credential appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Lakshmanan, R. 2026. FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation. The Hacker News, 23 June 2026.

2. Lakshmanan, R. 2026. FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations. The Hacker News, 2 July 2026.

3. SOCRadar. 2026. FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations. SOCRadar Blog, 2 July 2026.

Share this article