430,000 FortiGate firewalls. Not endpoints. Not servers. The devices meant to stop this.

The FortiBleed credential-theft campaign has now been linked directly to the INC and Lynx ransomware operations. This was never a smash-and-grab. It was reconnaissance at industrial scale, and the payload is arriving now.

WHAT THE CAMPAIGN ACTUALLY DID

Attackers harvested credentials from more than 430,000 FortiGate devices worldwide. On roughly 19,000 of them, they went further and deployed traffic sniffers directly on the firewall itself — reading VPN sessions, admin logins, and internal traffic metadata passing through the one device every other security control assumes is trustworthy.

The credentials sat dormant. Now they are fueling follow-on intrusions from established ransomware crews.

WHY A FIREWALL SNIFFER IS WORSE THAN AN ENDPOINT ONE

A compromised endpoint gives an attacker one user's view of the network. A compromised firewall sees every session that crosses it — every VPN authentication, every internal-to-DMZ flow, every credential in transit that assumes the perimeter device is clean.

Your firewall is the trust anchor your entire security architecture is built on. FortiBleed turned 19,000 of them into collection points.

HOW TO RESPOND

ASSUME CREDENTIAL COMPROMISE — if your FortiGate was ever exposed to the vulnerable firmware window, rotate every credential that ever authenticated through it. VPN, admin, RADIUS, all of it.

CHECK FOR SNIFFER ARTIFACTS — review FortiGate configuration for unauthorized packet capture jobs, unexpected diagnostic sessions, and configuration changes outside your change window.

FORCE RE-AUTHENTICATION NETWORK-WIDE — do not wait for natural session expiry. Stale sessions are stolen sessions still in use.

HUNT FOR INC AND LYNX TTPS — these operations are known. Their indicators are published. Check for them specifically, not generically.

PATCH AND VALIDATE FIRMWARE VERSIONS FLEET-WIDE — one unpatched device in a multi-site deployment reopens the entire campaign's access.

The perimeter device stopped being neutral ground the moment attackers realized it sees more than anything behind it.

Has your team rotated every credential that touched a FortiGate this year?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.