Dormant High impact Data breach Checked 1w ago

Mass FortiGate credential leak fuels ransomware, UK breach

A campaign called FortiBleed harvested login credentials for roughly 74,000 to 86,000 internet-facing Fortinet FortiGate firewalls and VPNs worldwide, first reported in June 2026. Researchers say the stolen credentials are now being reused by the INC and Lynx ransomware gangs, and press reports say Russian-linked hackers used the same leaked logins to reach UK government and Foreign Office email accounts. US and UK cyber agencies have urged affected organizations to reset passwords and turn on multi-factor authentication.

Started
Jun 17, 2026
Latest activity
Jul 8, 2026
Attributed to
INC and Lynx ransomware gangs; Russia-linked actors suspected in the UK breachSuspected
Where
Worldwide, United Kingdom, United States
Sectors
Government, Energy, Healthcare, Technology, Multiple sectors
Scale
roughly 74,000 to 86,000 exposed Fortinet FortiGate firewall and VPN device credentials worldwide, described as about half of

Current status

As of July 8, 2026, researchers warned the leaked credentials still posed an elevated risk to maritime and energy infrastructure operators, and no closure or full remediation has been announced.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Security researchers cited by BleepingComputer, SecurityWeek and Dark Reading say the stolen FortiGate credentials are being reused by the INC and Lynx ransomware operations; the Telegraph reported Russian-linked hackers used the same leak against UK government accounts, but no government has confirmed state attribution.

Impact

The leak has been tied to a confirmed breach of UK government and Foreign Office email accounts, and researchers say it is seeding follow-on ransomware intrusions by the INC and Lynx gangs; no specific ransomware victim or service outage has been publicly named yet.

What to do

If your organization runs a FortiGate firewall or VPN, reset all admin and user credentials now, enable multi-factor authentication, and check CISA's and NCSC's FortiBleed advisories for exposure indicators.

Timeline

  1. Aug 3, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Aug 2, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  3. Aug 1, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  4. Jul 8, 2026

    Cydome warns the leaked credentials pose elevated risk to maritime and energy critical-infrastructure operators.

    Activehstoday.us
  5. Jul 6, 2026

    The Telegraph reports Russian-linked hackers used leaked FortiBleed credentials to access UK government and Foreign Office email accounts, described as a major national security breach.

    Activemsn.com
  6. Jul 2, 2026

    SOCRadar said it found an operator with access to the stolen FortiBleed credentials working negotiation panels for both the INC and Lynx ransomware groups, confirming stolen access is being used for ransomware intrusions.

    Activesocradar.io
  7. Jul 2, 2026

    Researchers report the stolen FortiBleed credentials are being reused by the INC and Lynx ransomware operations.

    Activesecurityweek.com
  8. Jul 1, 2026

    SOCRadar's Threat Research Unit reported a FortiBleed-linked operator was found running negotiation panels for the INC Ransom and Lynx ransomware operations, tying the stolen credentials to active ransomware attacks for the first time.

    Activebleepingcomputer.com
  9. Jul 1, 2026

    BleepingComputer reported the FortiBleed credential theft campaign had been linked to the INC and Lynx ransomware operations.

    Activebleepingcomputer.com
  10. Jun 23, 2026

    Researchers reported the FortiBleed campaign had touched more than 430,000 FortiGate firewalls and harvested over 110 million credentials.

    Activethehackernews.com
  11. Jun 23, 2026

    Dark Reading reported the FortiBleed operators had built a sniffer tool to passively harvest credentials from a broader set of compromised FortiGate devices than first known.

    Activedarkreading.com
  12. Jun 22, 2026

    The UK's NCSC urges Fortinet customers to reset credentials and enable multi-factor authentication.

    Activeinfosecurity-magazine.com
  13. Jun 19, 2026

    SecurityWeek and other outlets reported that credentials for roughly 74,000 to 86,000 Fortinet firewalls and VPN gateways had been exposed.

    Emergingsecurityweek.com
  14. Jun 19, 2026

    CISA says roughly 74,000 to 86,000 Fortinet device credentials were exposed in the leak, dubbed FortiBleed, and Fortinet says it is not tied to a new vulnerability.

    Activebleepingcomputer.com
  15. Jun 18, 2026

    CISA warned that malicious actors were using leaked credentials to target roughly 74,000 internet-accessible Fortinet firewalls and VPN gateways.

    Emergingcisa.gov
  16. Jun 18, 2026

    CISA issued an alert urging Fortinet customers to harden internet-facing FortiGate devices after reports of a large credential exposure campaign called FortiBleed.

    Emergingcisa.gov
  17. Jun 17, 2026

    Fortinet confirms a large-scale credential-harvesting campaign is targeting its FortiGate firewalls and VPNs, and researchers say prominent organizations were hit.

    Emergingreuters.com

Sources

Related reports