Filed under: Cybersecurity · Network Security · July 2026
What happened
Researchers investigating “FortiBleed” — a massive credential-theft operation against Fortinet FortiGate firewalls — have now tied it directly to the INC and Lynx ransomware gangs. The attackers planted a traffic-sniffing tool on compromised firewalls to intercept VPN usernames and passwords as employees logged in, harvesting credentials from more than 73,000 devices; the operation targeted over 430,000 firewalls worldwide. Roughly 11,000 devices are believed to still be compromised, and investigators found backdoor admin accounts named “adminin” left behind on affected systems. This is confirmed real-world activity, not a proof of concept.
Why it matters to your business
FortiGate firewalls are common in small offices, often installed by a vendor years ago and rarely touched since. If yours was compromised, the passwords your staff use to connect remotely are sitting in a criminal database — and the groups holding them are ransomware operators whose business is getting into networks and encrypting everything. A firewall that was “fixed” by only changing passwords can still be compromised: if the sniffer is still on the device, new passwords get stolen too.
What to do this week
If your office firewall is a Fortinet: update it to the latest FortiOS firmware for your model, then — in that order — reset every VPN and admin password, since credentials changed before patching may already be captured. Check System → Administrators for any account you don’t recognize (especially “adminin”) and remove it. Turn on multi-factor authentication for VPN logins, and make sure the management interface isn’t reachable from the internet. Not sure what brand your firewall is or who manages it? Find out today — that answer shouldn’t be a mystery.
The bigger picture
Stolen credentials are the raw material of ransomware: gangs don’t need to hack your network if they can simply log in. Once they’re inside, recovery gets expensive fast — prevention is the only plan that reliably works. → Why the Only True Recovery from Ransomware Is Prevention
Who last checked what’s running on your office firewall — and when? Book a free consult → https://micro1tech.com/contact/