Skip to content
You can now search across every topic, entity and event.What's new
INC Ransom
Organisation

INC Ransom

Double-extortion ransomware crew, active since 2023, whose leak-site operator also runs Lynx's negotiation panels.

Last refreshed: 14 July 2026 · Appears in 1 active topic

Key Question

Two ransomware brands, one operator: how tied is INC Ransom really to Lynx?

Timeline for INC Ransom

#10 8 Jul

Shared a negotiation-panel operator with INC Ransom

Cybersecurity: Threats and Defences: One operator ran both ransomware brands
#9 4 Jul

Mentioned in: BOD 26-04, a fortnight of triage

Cybersecurity: Threats and Defences
#9 1 Jul

Lynx crew cashes in FortiBleed haul

Cybersecurity: Threats and Defences
#6 31 May

Mentioned in: Ransomware tempo holds at 95 in May

Cybersecurity: Threats and Defences
View full timeline →

Background

INC Ransom is a double-extortion ransomware crew that emerged in mid-2023, encrypting victim systems and threatening to publish stolen data on its dark-web leak site unless a ransom is paid. It claimed its first notable healthcare victims in 2024, attacking NHS Scotland's Dumfries and Galloway NHS Board and NHS Lanarkshire, which drew ICO scrutiny and NCSC guidance. The group has continued targeting UK organisations since, posting manufacturer Stuga Machinery on 5 June 2026, the only in-window UK victim confirmed in BlackFog's May tempo data.

INC Ransom relies on living-off-the-land binaries for lateral movement and customises its ransomware payload per victim. Its principal sectors are healthcare, manufacturing, professional services and government, spanning North America and Europe.

SOCRadar attributed the FortiBleed campaign, the theft of 86,644 FortiGate credentials flagged privately by NCSC and CISA in June 2026, to the Lynx ransomware crew, a separate brand that shares code lineage with INC Ransom. Lynx cracked the credentials offline on a 45-GPU Hashtopolis cluster, exploiting legacy SHA-256 FortiOS hashes never re-hashed to PBKDF2 after Fortinet's 2025 upgrade, scanning roughly 11,250 FortiGate portals across more than 150 countries. SOCRadar confirmed admin-level access on 409 targets and a completed attack chain on 354.

On 8 July 2026, SOCRadar went further, finding a single operator running the negotiation panels for both INC Ransom and Lynx, the first confirmed link between the mass credential theft and live ransomware deployment: at least 12 confirmed deployments split across the two brands. INC Ransom and Lynx remain distinct crews with separate leak sites, tied together by shared tooling and, now, at least one shared operator.

Common Questions
Is Lynx ransomware the same group as INC Ransom?
No. Lynx and INC Ransom are separate ransomware brands with their own leak sites, but SOCRadar found they share code lineage and, as of July 2026, one operator running both groups' negotiation panels.Source: SOCRadar
How many organisations has the FortiBleed access chain reached so far?
SOCRadar confirmed admin-level access on 409 targets, completed a full attack chain on 354, and counted at least 12 resulting ransomware deployments.Source: SOCRadar
How did the Lynx/INC crew get hold of 86,644 FortiGate passwords?
They cracked the credentials offline on a 45-GPU Hashtopolis cluster, exploiting legacy SHA-256 FortiOS hashes never re-hashed to PBKDF2.Source: SOCRadar
What should a company do if INC_RANSOM posts it on their leak site?
A leak-site posting means INC_RANSOM is asserting it has stolen data and is using the threat of publication as leverage. Affected organisations should immediately engage a specialist Incident Response firm, notify the ICO within 72 hours under UK GDPR Article 33, preserve all forensic evidence, and seek specialist legal advice before any ransom payment consideration. Payment does not guarantee data deletion.Source: NCSC incident response guidance, ICO breach notification requirements
What is INC_RANSOM and which organisations has it attacked?
INC_RANSOM is a double-extortion ransomware group active since mid-2023. It encrypts victim systems and threatens to publish stolen data on a dark-web leak site. Notable victims include NHS Scotland in early 2024 and UK manufacturer Stuga Machinery posted in June 2026. The group targets healthcare, manufacturing and professional services in North America and Europe.Source: NCSC guidance, NHS Scotland incident reporting, BlackFog ransomware report
What did SOCRadar find about INC Ransom and Lynx sharing an operator?
On 8 July 2026, SOCRadar reported a single operator running the negotiation panels for both INC Ransom and Lynx, the first confirmed link tying the FortiBleed credential haul to live ransomware deployment across both brands.Source: SOCRadar
Did INC_RANSOM attack the NHS?
Yes. In early 2024, INC_RANSOM attacked NHS Scotland, specifically Dumfries and Galloway NHS Board and NHS Lanarkshire, encrypting systems and stealing patient data. The group threatened to publish the stolen data. The incidents prompted NCSC guidance and ICO scrutiny. INC_RANSOM continued UK targeting in June 2026 with the posting of manufacturer Stuga Machinery.Source: NHS Scotland incident reports, NCSC advisory
Source Material