Somewhere between 2023 and today, hundreds of thousands of FortiGate firewalls quietly leaked their credentials to whoever bothered to ask. Nobody rushed to rotate those passwords. Now two ransomware operations, INC and Lynx, are cashing in on that inertia, using harvested Fortinet credentials to walk straight past the perimeter and into networks that thought their edge devices were locked down. This is what happens when a cybersecurity control turns into the attacker’s on-ramp: the device meant to keep intruders out becomes the thing that lets them in.

A Firewall Flaw Leaked Passwords. Ransomware Gangs Cashed The Check.
Researchers are now calling this the FortiBleed campaign, and the name tells you exactly what it does: a memory-disclosure flaw in FortiGate appliances quietly exposes data it shouldn’t, including credentials, and attackers have been scraping that leaked material at scale for years. The scale is the part that should stop you cold.
Researchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations.
Hundreds of thousands of devices. Not a handful of misconfigured boxes at a regional hospital chain, but a pool of credentials broad enough that two separate ransomware crews independently built business models around it. INC and Lynx don’t need to phish anyone or write a slick exploit chain. They need a list of valid VPN credentials pulled from leaked firewall memory, and a firewall admin somewhere who never rotated a password after the original vulnerability was patched.
That last detail is the real story. Patching the flaw stopped the leak. It did nothing about the credentials that had already leaked before the patch went in. A firewall fixed in 2024 can still be handing attackers a front door in 2026, because the fix addressed the vulnerability and ignored the blast radius.
You Patched The Firewall. The Stolen Password Still Works.
This is the pattern that keeps repeating across the industry, and it’s why treating patch compliance as the finish line of your threat-protection program is a mistake. A CVE gets a fix. Everyone breathes out. Meanwhile the actual asset attackers wanted, the credential, never expires, never rotates, and never shows up on a vulnerability scan because a scanner checks firmware versions, not password freshness.
Firewalls make this worse than almost any other device class because of what sits behind them. A compromised VPN or SSL-VPN login on a FortiGate box isn’t a foothold on one workstation. It’s often a straight line to the internal network, sometimes with admin-level reach into the exact segmentation controls that were supposed to contain an intrusion. INC and Lynx aren’t spending weeks doing reconnaissance once they’re in. They already know they’re behind the firewall, which means they’re already past the control most incident response plans assume is intact.
Defense in depth exists precisely for this scenario: the assumption that any single control, including the firewall itself, will eventually fail or be bypassed. Too many organizations built their edge security around the firewall being the last word rather than one layer among several. When the layer you trusted most turns out to be leaking your keys, everything behind it is exposed by default, not by additional attacker effort.
It’s worth being blunt about the brute-force angle too, because these two threats compound each other. Stolen credentials from a leak get sprayed against remaining accounts, weak or reused passwords get caught in brute-force sweeps, and threat detection tuned only to flag failed logins misses the accounts that just work on the first try because the password was never anyone’s guess, it was already known.
What Actually Stops This: Rotate Before You’re Asked To
The fix here isn’t exotic. It’s discipline that most security teams already know and routinely skip because rotating credentials on a production firewall feels disruptive. It’s less disruptive than a ransomware note.
- Rotate every credential exposed to a firewall or VPN appliance that has ever carried a memory-disclosure or credential-leak CVE, regardless of whether you patched the flaw months ago. The patch stops future leaks. It doesn’t undo past ones.
- Force a password reset for all local and VPN accounts on edge devices on a recurring schedule, not just after an incident. Treat rotation as routine security hardening, the same way you’d rotate a service account key.
- Enable phishing-resistant MFA on every VPN and management login on the perimeter. A leaked password is useless if it can’t authenticate alone.
- Turn on detailed authentication logging on the firewall itself and ship it somewhere the firewall’s own compromise can’t erase it. If the appliance is the attacker’s foothold, logs stored only on that appliance are compromised too.
- Watch for logins from unfamiliar geographies or ASNs against VPN accounts that normally only connect from a handful of known locations. This is one of the highest-signal, lowest-noise indicators available for this exact attack pattern.
- Segment what a compromised VPN session can actually reach. If a remote-access login lands a user directly on the flat internal network, you’ve built your incident response plan around a control that, per this campaign, doesn’t hold.
None of this requires a new product. It requires accepting that a patched CVE and a secure environment are not the same statement, and that credential rotation belongs in the same operational rhythm as patch management, not as a one-time cleanup task after a breach notification lands in your inbox.
INC and Lynx didn’t invent a new technique here. They found an inventory of valid keys that nobody bothered to change, and they’re working through it methodically. The organizations that get hit next won’t be the ones that failed to patch. They’ll be the ones that patched, felt done, and never asked what the vulnerability had already handed away before the fix arrived.
Sources
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
