
Lynx
Ransomware-as-a-service crew; shares an operator and code lineage with INC Ransom.
Lynx is a ransomware-as-a-service crew that surfaced in mid-2024, running its own leak site and negotiation panel. On 8 July 2026, SOCRadar found the same operator working Lynx's negotiations and INC Ransom's, the first confirmed tie between the two brands.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Same operator, two ransomware brands: is Lynx really separate from INC Ransom?
Timeline for Lynx
Mentioned in: CISA's KEV list runs a month late
Cybersecurity: Threats and DefencesOne operator ran both ransomware brands
Cybersecurity: Threats and DefencesBackground
Lynx is a ransomware-as-a-service operation that surfaced in mid-2024, running its own dark-web leak site, its own victim postings and its own negotiation panel under a double-extortion model: encrypt, exfiltrate, then threaten publication. Analysts have long flagged code-lineage overlap between Lynx and the older INC Ransom crew, though the two have kept separate public identities and victim lists.
Lynx's present relevance rests on the FortiBleed campaign. SOCRadar traced the theft of 86,644 FortiGate credentials, cracked offline on a 45-GPU cluster after Fortinet Left a legacy hashing scheme unpatched, to admin-level access on 409 targets and a completed attack chain on 354.
On 8 July 2026, SOCRadar reported that a single individual staffed the negotiation side of both Lynx and INC Ransom, converting part of that credential haul into at least 12 confirmed ransomware deployments split across the two brands. The overlap is a staffing finding, not a merger: Lynx still runs its own leak site and sets its own terms.