CARDS
CARDS
FortiBleed is retained as a Fortinet/FortiGate credential-exposure campaign in which public reporting tied exposed or stolen Fortinet edge credentials to downstream ransomware activity involving INC Ransom and Lynx. IntelliOS treats FortiBleed as a campaign/operation context rather than proof that every exposed Fortinet environment was compromised or deployed with ransomware.
Last updated Jul 08, 2026, 8:00 PM EDT
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
FortiBleed is retained as campaign context and exposure/ransomware linkage reporting. IntelliOS does not republish raw exposed-instance lists, credentials, victim lists, leak-site data, or unsupported claims.
IntelliOS
Citations