Researchers have confirmed what security teams feared when FortiBleed first surfaced: the mass credential-harvesting campaign against Fortinet firewalls is directly feeding at least two active ransomware operations.
FortiBleed targets internet-facing FortiGate firewalls and their SSL VPN gateways. Attackers planted a custom packet-sniffing tool, nicknamed FortiGate Sniffer, on compromised devices to intercept VPN login credentials straight out of network traffic. The campaign is assessed to have touched roughly 430,000 FortiGate firewalls worldwide, harvesting more than 110 million credentials in the process.
Threat intelligence firm SOCRadar has now tied the operator behind FortiBleed's infrastructure to negotiation panels used by both INC Ransom and Lynx, two Russian-speaking ransomware-as-a-service groups. At least 12 confirmed ransomware deployments using FortiBleed-sourced credentials have been traced so far, hitting manufacturing, technology and logistics organisations with hundreds of encrypted endpoints between them.
If your organisation runs FortiGate firewalls for remote access, this is not a theoretical risk sitting in a research report, it is an active pipeline into ransomware deployment. Patch to the latest firmware, and treat every VPN credential that has touched an internet-facing FortiGate device as potentially compromised. Rotate them rather than waiting for confirmation that yours specifically was caught.
For everyone else, the lesson travels: edge devices like firewalls and VPN gateways are now a preferred entry point precisely because they sit outside normal endpoint monitoring. If your workplace uses any perimeter hardware, ask whether it's on the latest firmware. It usually isn't.