
INC Ransom
Double-extortion ransomware crew, active since 2023, whose leak-site operator also runs Lynx's negotiation panels.
Last refreshed: 14 July 2026 · Appears in 1 active topic
Two ransomware brands, one operator: how tied is INC Ransom really to Lynx?
Timeline for INC Ransom
Shared a negotiation-panel operator with INC Ransom
Cybersecurity: Threats and Defences: One operator ran both ransomware brandsMentioned in: BOD 26-04, a fortnight of triage
Cybersecurity: Threats and DefencesLynx crew cashes in FortiBleed haul
Cybersecurity: Threats and DefencesMentioned in: Ransomware tempo holds at 95 in May
Cybersecurity: Threats and DefencesBackground
INC Ransom is a double-extortion ransomware crew that emerged in mid-2023, encrypting victim systems and threatening to publish stolen data on its dark-web leak site unless a ransom is paid. It claimed its first notable healthcare victims in 2024, attacking NHS Scotland's Dumfries and Galloway NHS Board and NHS Lanarkshire, which drew ICO scrutiny and NCSC guidance. The group has continued targeting UK organisations since, posting manufacturer Stuga Machinery on 5 June 2026, the only in-window UK victim confirmed in BlackFog's May tempo data.
INC Ransom relies on living-off-the-land binaries for lateral movement and customises its ransomware payload per victim. Its principal sectors are healthcare, manufacturing, professional services and government, spanning North America and Europe.
SOCRadar attributed the FortiBleed campaign, the theft of 86,644 FortiGate credentials flagged privately by NCSC and CISA in June 2026, to the Lynx ransomware crew, a separate brand that shares code lineage with INC Ransom. Lynx cracked the credentials offline on a 45-GPU Hashtopolis cluster, exploiting legacy SHA-256 FortiOS hashes never re-hashed to PBKDF2 after Fortinet's 2025 upgrade, scanning roughly 11,250 FortiGate portals across more than 150 countries. SOCRadar confirmed admin-level access on 409 targets and a completed attack chain on 354.
On 8 July 2026, SOCRadar went further, finding a single operator running the negotiation panels for both INC Ransom and Lynx, the first confirmed link between the mass credential theft and live ransomware deployment: at least 12 confirmed deployments split across the two brands. INC Ransom and Lynx remain distinct crews with separate leak sites, tied together by shared tooling and, now, at least one shared operator.