Skip to content
You can now search across every topic, entity and event.What's new
SOCRadar
OrganisationUS

SOCRadar

Threat-intelligence firm that traced FortiBleed credentials to confirmed ransomware deployments and a shared operator.

SOCRadar is a threat-intelligence firm that traced the FortiBleed credential haul to live ransomware attacks. On 8 July 2026 it found one operator running negotiation panels for both INC Ransom and Lynx, the first proof the haul had converted into deployed attacks.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

What did SOCRadar's FortiBleed analysis reveal about the Russian-attributed targeting?

Timeline for SOCRadar

#11 16 Jul

Mentioned in: CISA's KEV list runs a month late

Cybersecurity: Threats and Defences
#10 8 Jul

Reported 12 confirmed ransomware deployments from the FortiBleed haul

Cybersecurity: Threats and Defences: One operator ran both ransomware brands
#9 1 Jul

Attributed the 86,644-credential FortiGate harvest to Lynx/INC Ransom

Cybersecurity: Threats and Defences: Lynx crew cashes in FortiBleed haul
#8 18 Jun
View full timeline →

Background

SOCRadar is a threat-intelligence and attack-surface management firm founded in 2018, headquartered in the United States with development teams in Turkey. It specialises in dark-web monitoring, external attack-surface mapping and breach-data analysis for enterprise security teams. In June 2026 it published the first detailed technical analysis of the FortiBleed dataset, 86,644 stolen Fortinet FortiGate credentials spanning 194 countries, identifying revenue-band, employee-count and sector tags in the records that pointed to intelligence-preparation profiling rather than opportunistic criminal targeting.

Its core business is monitoring criminal infrastructure, dark-web forums and paste sites for leaked credentials and threat-actor communications, then alerting client organisations when they or their supply chain appear in that data. On 8 July 2026 that monitoring paid off again: SOCRadar found a single operator running the negotiation panels for both the INC Ransom and Lynx ransomware brands, the first confirmed evidence tying the FortiBleed haul to completed attacks rather than a dormant credential list.

The firm's Turkey-based development team gives it denser visibility into Russian-speaking criminal forums than some US-headquartered rivals such as Recorded Future or Intel 471, an advantage that showed in how early it reached the FortiBleed attribution, ahead of the joint NCSC-CISA advisory on 18 June 2026.

Common Questions
What is SOCRadar and what kind of threats does it track?
SOCRadar is a threat-intelligence platform founded in 2018 that monitors dark-web forums, criminal infrastructure, and breach databases to alert enterprise clients about leaked credentials and external attack-surface exposure. It is known for early detection of credential datasets before they are publicly dumped.Source: SOCRadar official description
What did SOCRadar discover about the Fortinet FortiBleed database?
SOCRadar published analysis of FortiBleed, a privately-held database of 86,644 Fortinet FortiGate credentials across 194 countries. It identified that the dataset included organisation revenue bands, employee counts, and sector tags, metadata that indicates intelligence-preparation profiling by a Russian-speaking actor rather than opportunistic ransomware.Source: SOCRadar FortiBleed analysis, June 2026
Why does SOCRadar have good coverage of Russian cybercrime forums?
SOCRadar's development team is based in Turkey, which gives the firm linguistic and operational proximity to Russian-speaking criminal infrastructure. This geographic footprint provides earlier visibility into Russian-attributed campaigns compared with US-headquartered competitors.Source: SOCRadar operational model
How did SOCRadar's FortiBleed findings relate to government alerts?
SOCRadar's technical analysis contributed to the attribution and characterisation of FortiBleed before NCSC and CISA issued joint alerts on 18 June 2026. SOCRadar identified the profiling metadata that made the dataset look like intelligence preparation rather than opportunistic crime.Source: SOCRadar FortiBleed report and NCSC/CISA joint advisory
What did SOCRadar find about ransomware operators sharing negotiation panels?
On 8 July 2026, SOCRadar reported that a single operator ran the negotiation panels for both INC Ransom and Lynx, the first hard link tying the FortiBleed credential haul to confirmed ransomware deployments rather than a dormant hit list.Source: SOCRadar
Source Material