
SOCRadar
Threat-intelligence firm that traced FortiBleed credentials to confirmed ransomware deployments and a shared operator.
SOCRadar is a threat-intelligence firm that traced the FortiBleed credential haul to live ransomware attacks. On 8 July 2026 it found one operator running negotiation panels for both INC Ransom and Lynx, the first proof the haul had converted into deployed attacks.
Last refreshed: 3 August 2026 · Appears in 1 active topic
What did SOCRadar's FortiBleed analysis reveal about the Russian-attributed targeting?
Timeline for SOCRadar
Mentioned in: CISA's KEV list runs a month late
Cybersecurity: Threats and DefencesReported 12 confirmed ransomware deployments from the FortiBleed haul
Cybersecurity: Threats and Defences: One operator ran both ransomware brandsAttributed the 86,644-credential FortiGate harvest to Lynx/INC Ransom
Cybersecurity: Threats and Defences: Lynx crew cashes in FortiBleed haulMentioned in: 86,644 Fortinet logins become a hit list
Cybersecurity: Threats and DefencesBackground
SOCRadar is a threat-intelligence and attack-surface management firm founded in 2018, headquartered in the United States with development teams in Turkey. It specialises in dark-web monitoring, external attack-surface mapping and breach-data analysis for enterprise security teams. In June 2026 it published the first detailed technical analysis of the FortiBleed dataset, 86,644 stolen Fortinet FortiGate credentials spanning 194 countries, identifying revenue-band, employee-count and sector tags in the records that pointed to intelligence-preparation profiling rather than opportunistic criminal targeting.
Its core business is monitoring criminal infrastructure, dark-web forums and paste sites for leaked credentials and threat-actor communications, then alerting client organisations when they or their supply chain appear in that data. On 8 July 2026 that monitoring paid off again: SOCRadar found a single operator running the negotiation panels for both the INC Ransom and Lynx ransomware brands, the first confirmed evidence tying the FortiBleed haul to completed attacks rather than a dormant credential list.
The firm's Turkey-based development team gives it denser visibility into Russian-speaking criminal forums than some US-headquartered rivals such as Recorded Future or Intel 471, an advantage that showed in how early it reached the FortiBleed attribution, ahead of the joint NCSC-CISA advisory on 18 June 2026.