Skip to content
You can now search across every topic, entity and event.What's new
Lynx
Organisation

Lynx

Ransomware-as-a-service crew; shares an operator and code lineage with INC Ransom.

Lynx is a ransomware-as-a-service crew that surfaced in mid-2024, running its own leak site and negotiation panel. On 8 July 2026, SOCRadar found the same operator working Lynx's negotiations and INC Ransom's, the first confirmed tie between the two brands.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Same operator, two ransomware brands: is Lynx really separate from INC Ransom?

Timeline for Lynx

#11 16 Jul

Mentioned in: CISA's KEV list runs a month late

Cybersecurity: Threats and Defences
#10 8 Jul

One operator ran both ransomware brands

Cybersecurity: Threats and Defences
View full timeline →

Background

Lynx is a ransomware-as-a-service operation that surfaced in mid-2024, running its own dark-web leak site, its own victim postings and its own negotiation panel under a double-extortion model: encrypt, exfiltrate, then threaten publication. Analysts have long flagged code-lineage overlap between Lynx and the older INC Ransom crew, though the two have kept separate public identities and victim lists.

Lynx's present relevance rests on the FortiBleed campaign. SOCRadar traced the theft of 86,644 FortiGate credentials, cracked offline on a 45-GPU cluster after Fortinet Left a legacy hashing scheme unpatched, to admin-level access on 409 targets and a completed attack chain on 354.

On 8 July 2026, SOCRadar reported that a single individual staffed the negotiation side of both Lynx and INC Ransom, converting part of that credential haul into at least 12 confirmed ransomware deployments split across the two brands. The overlap is a staffing finding, not a merger: Lynx still runs its own leak site and sets its own terms.

Common Questions
Is Lynx ransomware the same group as INC Ransom?
No. Lynx and INC Ransom are separate brands with their own leak sites, but SOCRadar found in July 2026 that they share code lineage and one operator running both groups' negotiation panels.Source: SOCRadar
What is the Lynx ransomware group?
Lynx is a ransomware-as-a-service crew active since mid-2024, running double-extortion attacks (encrypt then threaten to leak data) from its own dark-web leak site.Source: SOCRadar
How is Lynx connected to the FortiBleed breach?
SOCRadar found that Lynx and INC Ransom share one operator, who ran negotiation panels for both, and traced 12 confirmed ransomware deployments from the FortiBleed FortiGate credential haul to the two brands.Source: SOCRadar
When did Lynx ransomware first appear?
Lynx surfaced roughly a year after INC Ransom, which emerged in mid-2023, putting Lynx's debut at around mid-2024.Source: SOCRadar