Mass FortiGate credential leak fuels ransomware, UK breach
A campaign called FortiBleed harvested login credentials for roughly 74,000 to 86,000 internet-facing Fortinet FortiGate firewalls and VPNs worldwide, first reported in June 2026. Researchers say the stolen credentials are now being reused by the INC and Lynx ransomware gangs, and press reports say Russian-linked hackers used the same leaked logins to reach UK government and Foreign Office email accounts. US and UK cyber agencies have urged affected organizations to reset passwords and turn on multi-factor authentication.
- Started
- Jun 17, 2026
- Latest activity
- Jul 8, 2026
- Attributed to
- INC and Lynx ransomware gangs; Russia-linked actors suspected in the UK breachSuspected
- Where
- Worldwide, United Kingdom, United States
- Sectors
- Government, Energy, Healthcare, Technology, Multiple sectors
- Scale
- roughly 74,000 to 86,000 exposed Fortinet FortiGate firewall and VPN device credentials worldwide, described as about half of
Current status
As of July 8, 2026, researchers warned the leaked credentials still posed an elevated risk to maritime and energy infrastructure operators, and no closure or full remediation has been announced.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Security researchers cited by BleepingComputer, SecurityWeek and Dark Reading say the stolen FortiGate credentials are being reused by the INC and Lynx ransomware operations; the Telegraph reported Russian-linked hackers used the same leak against UK government accounts, but no government has confirmed state attribution.
Impact
The leak has been tied to a confirmed breach of UK government and Foreign Office email accounts, and researchers say it is seeding follow-on ransomware intrusions by the INC and Lynx gangs; no specific ransomware victim or service outage has been publicly named yet.
What to do
If your organization runs a FortiGate firewall or VPN, reset all admin and user credentials now, enable multi-factor authentication, and check CISA's and NCSC's FortiBleed advisories for exposure indicators.
Timeline
-
Aug 3, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 2, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 1, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 8, 2026
Cydome warns the leaked credentials pose elevated risk to maritime and energy critical-infrastructure operators.
Activehstoday.us -
Jul 6, 2026
The Telegraph reports Russian-linked hackers used leaked FortiBleed credentials to access UK government and Foreign Office email accounts, described as a major national security breach.
Activemsn.com -
Jul 2, 2026
SOCRadar said it found an operator with access to the stolen FortiBleed credentials working negotiation panels for both the INC and Lynx ransomware groups, confirming stolen access is being used for ransomware intrusions.
Activesocradar.io -
Jul 2, 2026
Researchers report the stolen FortiBleed credentials are being reused by the INC and Lynx ransomware operations.
Activesecurityweek.com -
Jul 1, 2026
SOCRadar's Threat Research Unit reported a FortiBleed-linked operator was found running negotiation panels for the INC Ransom and Lynx ransomware operations, tying the stolen credentials to active ransomware attacks for the first time.
Activebleepingcomputer.com -
Jul 1, 2026
BleepingComputer reported the FortiBleed credential theft campaign had been linked to the INC and Lynx ransomware operations.
Activebleepingcomputer.com -
Jun 23, 2026
Researchers reported the FortiBleed campaign had touched more than 430,000 FortiGate firewalls and harvested over 110 million credentials.
Activethehackernews.com -
Jun 23, 2026
Dark Reading reported the FortiBleed operators had built a sniffer tool to passively harvest credentials from a broader set of compromised FortiGate devices than first known.
Activedarkreading.com -
Jun 22, 2026
The UK's NCSC urges Fortinet customers to reset credentials and enable multi-factor authentication.
Activeinfosecurity-magazine.com -
Jun 19, 2026
SecurityWeek and other outlets reported that credentials for roughly 74,000 to 86,000 Fortinet firewalls and VPN gateways had been exposed.
Emergingsecurityweek.com -
Jun 19, 2026
CISA says roughly 74,000 to 86,000 Fortinet device credentials were exposed in the leak, dubbed FortiBleed, and Fortinet says it is not tied to a new vulnerability.
Activebleepingcomputer.com -
Jun 18, 2026
CISA warned that malicious actors were using leaked credentials to target roughly 74,000 internet-accessible Fortinet firewalls and VPN gateways.
Emergingcisa.gov -
Jun 18, 2026
CISA issued an alert urging Fortinet customers to harden internet-facing FortiGate devices after reports of a large credential exposure campaign called FortiBleed.
Emergingcisa.gov -
Jun 17, 2026
Fortinet confirms a large-scale credential-harvesting campaign is targeting its FortiGate firewalls and VPNs, and researchers say prominent organizations were hit.
Emergingreuters.com
Sources
- Major hack campaign against Fortinet devices compromised prominent organisations, researchers say Reuters Jun 17, 2026 unverified
- CISA warns Fortinet users to secure devices after FortiBleed leak BleepingComputer Jun 19, 2026
- FortiBleed: 86,000 Fortinet Device Credentials Compromised SecurityWeek Jun 19, 2026
- NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout Infosecurity Magazine Jun 22, 2026
- FortiBleed credential-theft campaign linked to Lynx ransomware BleepingComputer Jul 1, 2026
- FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks SecurityWeek Jul 2, 2026
- Russian hackers breach 80,000+ firewalls to steal UK government login credentials MSN (Telegraph) Jul 6, 2026
- Cydome Reports FortiBleed Credential Leak Poses Elevated Risks to Maritime and Energy Critical Infrastructure HSToday Jul 8, 2026 unverified
- CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure CISA Jun 18, 2026
- Fortinet FortiGate VPN attacks steal admin passwords VPNCentral Jun 19, 2026
- FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist Dark Reading Jun 23, 2026
- SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Operations SOCRadar Jul 2, 2026 unverified
- Analysis of Reported Credential Compromise of FortiGate Devices Fortinet Jun 18, 2026
- FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Campaign The Hacker News Jun 23, 2026
- FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs Dark Reading Jul 2, 2026
- Fortinet firewalls hacked to steal admin passwords Cyber Security News Jun 21, 2026
Related reports
- FortiBleed credential-theft campaign linked to Lynx ransomware Jul 1, 2026
- FortiGate firewalls leaking passwords to ransomware gangs Jul 1, 2026
- FortiGate firewalls hacked to steal credentials, link to ransomware Jul 1, 2026
- Fortinet leaked 86,000 device passwords Jun 19, 2026
- Fortinet FortiGate VPN attacks steal admin passwords Jun 19, 2026
- Fortinet devices leaking passwords after hack Jun 18, 2026
- Fortinet firewalls hacked in massive credential leak Jun 18, 2026