Ransomware: why VPNs and firewalls are the main way in
NetScaler, FortiMail, FortiBleed: in autumn 2026, ransomware gets in through internet-facing devices. What happened, and how to reduce this risk.
Ransomware is an attack that locks an organisation out of its systems, encrypts or copies its data, then demands a ransom. In autumn 2026, several of the most serious campaigns did not start with a booby-trapped email or an infected laptop: they came in through VPNs, firewalls and remote access gateways exposed to the internet. Here is why these devices have become the preferred way in, and what a CISO can do right now.
Ransomware: definition and how it works
According to the French government platform Cybermalveillance.gouv.fr, ransomware means compromising a device or an information system to block access to it, encrypt or copy its data, then demand payment in exchange for giving it back. Attackers no longer just encrypt: they steal the data first and threaten to publish it. This is double extortion, which makes backups necessary but no longer sufficient.
In France, ANSSI, the national cybersecurity agency, was made aware of 128 ransomware attacks in 2025, compared with 141 in 2024. The drop is misleading: these figures only count cases reported to the agency, and its 2025 cyber threat overview also records 460 possible data leak events. At European level, the ENISA Threat Landscape 2026 report ranks ransomware as the incident type with the most immediate impact: it accounts for 40% of the cybercrime events analysed in 2025.
The initial access broker → affiliate model
A ransomware attack is rarely the work of a single crew. The market has specialised. Initial access brokers take care of getting into the network: they exploit a flaw or use stolen credentials, check that the access works, then resell it. Affiliates buy it, move through the network, steal data and trigger encryption with ransomware leased from a criminal group.
The FBI and US Secret Service advisory of 6 October 2026 describes exactly this chain: the FortiBleed operation culminated in selling access to compromised networks, used as an “initial entry point” by INC/Lynx and Payload ransomware affiliates.
- EntryEdge device Exposed VPN, firewall or gateway: unpatched flaw or stolen credentials
- ResaleInitial access broker Checks the access, packages it and puts it up for sale
- IntrusionRansomware affiliate Buys the access, moves through the network, steals data
- RansomEncryption and extortion Systems encrypted, threat to publish the stolen data
More than 86,644 FortiGate firewalls compromised in 194 countries; access is sold to INC/Lynx and Payload ransomware affiliates.
FBI and US Secret Service, 6 October 2026Why edge devices are the preferred way in
Edge devices are the appliances sitting on the boundary between the internet and the internal network: SSL VPNs, firewalls, remote access gateways, email relays. They combine three traits that make them an ideal target:
- they are exposed by design: anyone can reach and scan them, at any time;
- they open onto the internal network and are often connected to the account directory, giving the attacker credentials from the start;
- they are less monitored than laptops and servers, even though a critical vulnerability can be exploited on them without authentication, sometimes in the default configuration.
ANSSI sums it up in its latest overview: edge devices “remain a highly prized target”. The agency also sees vulnerabilities exploited just hours after disclosure, especially on internet-facing devices. At European level, ENISA notes that exploiting known flaws or zero-day flaws “remains a prevalent intrusion vector”: when the vector of unauthorised access could be identified, it was a vulnerability in 60% of cases. And the volume is not falling: more than 48,000 new CVEs were published in 2025, 22% more than in 2024.
Autumn 2026: four alerts on critical VPN and firewall vulnerabilities
Citrix NetScaler: a zero-day flaw turned mass attack
CVE-2026-88771 and CVE-2026-88772 allow remote code execution on NetScaler ADC and Gateway appliances, without authentication. CERT-FR (alert CERTFR-2026-ALE-011) states that exploitation “began before patches were available” and that all devices are vulnerable in their default configuration. According to Help Net Security, Mandiant traces the first attacks, attributed to suspected state actors, back to early September. The release of a proof of concept then triggered a wave of opportunistic attacks.
- Early Sept. CVE-2026-88772 exploited as a zero-day Mandiant, suspected state actors
- 24 Sept. GreyNoise spots an exploitation attempt More than three days before public disclosure
- 27 Sept. Citrix advisory and patches; added to CISA KEV Federal deadline: 30 September
- 28 Sept. CERT-FR alert ALE-011; public proof of concept Mass attacks within minutes
- 29 Sept. Fewer than 10% of exposed hosts patched Over 100 victim organisations tracked
- 5 Oct. CERT-FR update: a third flaw exploited CVE-2026-88779, denial of service
Exposure is massive: Censys counts about 42,000 devices visible on the Internet, 13% of them in Germany. And as of 29 September, fewer than 10% of exposed hosts were patched according to researcher Kevin Beaumont, who was already tracking more than 100 victim organisations.
- United States 13,549 · 32%
- Germany 5,678 · 13%
- Netherlands ≈ 4%
- United Kingdom ≈ 4%
- Switzerland ≈ 4%
FortiBleed: access resold to ransomware affiliates
FortiBleed is not a flaw but a credential theft campaign. According to the FBI and the Secret Service, attackers scanned FortiGate SSL VPN portals, tried passwords from leaks and infostealer logs, dumped user databases, then cracked offline the passwords stored with a legacy SHA-256 hashing format. The toll, verified by SOCRadar: more than 86,644 compromised devices in 194 countries, and administrators sometimes locked out of their own firewalls.
FortiMail and SonicWall: when patching is not enough
On 1 October, Fortinet confirmed exploitation of CVE-2026-104286 (CVSS score 9.8) in its FortiMail email gateway: an unauthenticated attacker can write arbitrary files to the device. CISA added it to its KEV catalogue the same day. A month earlier, CERT-FR had warned of two actively exploited flaws in SonicWall SMA 1000 gateways (CERTFR-2026-ALE-009), with a clear instruction: applying the patches “is not sufficient”. It recommends reinstalling the system, changing all passwords and resetting TOTP secrets.
When the security tool becomes the way in
The case of the cryptocurrency exchange Bitget is not ransomware, but it illustrates the same logic. According to The Hacker News, attackers exploited a zero-day flaw in third-party security appliances, planted a web shell on them, then pivoted to the wallet servers: $387.5 million stolen. The devices meant to protect the perimeter are part of the perimeter to protect.
Require phishing-resistant MFA on all remote access and administrative accounts.
FBI and US Secret Service, FortiBleed advisory, 6 October 2026
Reducing ransomware risk: five priorities for the CISO
1. Inventory what is exposed. You cannot patch a device you do not know exists. List every VPN, firewall, gateway and email relay reachable from the internet, with its version, its owner and whether its admin interface is exposed. Cross-check with an external scan: that is what attackers see.
2. Prioritise patches using KEV and CERT-FR. Not all CVEs are equal. A flaw listed in the CISA KEV catalogue or covered by a CERT-FR alert is being exploited: it jumps the queue, with a deadline counted in hours for edge devices.
3. Harden access. The FBI recommends phishing-resistant MFA (FIDO2 security keys, smart cards) on remote access and administration, removing administration from the internet, ending active sessions and renewing passwords and API keys after an incident.
4. Hunt for compromise before and after patching. A patch shuts the door but does not evict an intruder who is already inside. CISA advises checking for indicators of compromise before patching and preserving evidence, as reported by BleepingComputer. Citrix itself acknowledges that the indicators of compromise it provides may miss actual compromises.
5. Prepare for the crisis. Offline backups and tested restores, a crisis plan known to senior management, contact details for your incident response provider. In the event of an attack, Cybermalveillance.gouv.fr advises disconnecting from the internet without switching machines off, not paying the ransom, filing a complaint and notifying the CNIL within 72 hours if personal data is affected.
Bringing the ransomware scenario into an EBIOS RM risk analysis
These measures make the most sense when they answer an explicit risk scenario approved by management. ANSSI's EBIOS Risk Manager method is well suited to this, especially its workshops 3 and 4:
- Workshop 3 (strategic scenarios): map the ecosystem. The firewall vendor, the managed service provider running the VPN or the supplier of a security tool are stakeholders whose threat level must be assessed. The “access broker → affiliate” path becomes a strategic scenario.
- Workshop 4 (operational scenarios): build the attack graph, from exploiting the VPN or reusing credentials through to data theft and encryption. Assess its likelihood with real data: whether the version is in KEV, CERT-FR alerts, share of devices patched.
Workshop 5 then turns the five priorities above into a treatment plan, with owners and deadlines. Our analysis of the CNIL fine against a hospital and our article on data breaches in the French State show what the lack of MFA on remote access costs.
How to prepare
A risk analysis is only valuable if it stays alive. With Phinasoft's risk analysis module, an EBIOS RM software labelled by ANSSI, the “ransomware through an edge device” scenario is built workshop by workshop and updated when a new alert comes out. The scenario is linked to the treatment plan, which can then be followed through compliance campaigns. And because the managed service provider or the vendor of a device is part of the attack surface, vendor risk management lets you check their own patching and authentication practices.
Frequently asked questions
What is ransomware?
It is an attack that compromises an information system to block access to it, encrypt or copy its data, then demand a ransom. Today, attackers often steal data before encrypting, so they can threaten to publish it.
Is “rançongiciel” different from ransomware?
No: rançongiciel is the French word for the same threat. It is the term used by ANSSI and Cybermalveillance.gouv.fr.
What is a zero-day flaw?
It is a vulnerability exploited by attackers before the vendor has released a patch. Defenders then have “zero days” to protect themselves: only workarounds, reduced exposure and monitoring limit the risk.
Is patching a VPN enough?
No, if the device was exposed during the exploitation window. The patch prevents new intrusions but removes neither a web shell nor an account created by the attacker. You need to look for signs of compromise, and sometimes reinstall the device and change every secret, as CERT-FR requires for SonicWall.
Should you pay the ransom?
French authorities advise against paying: nothing guarantees the data will be recovered, or that it will not be published. It is better to file a complaint, get expert support and restore from clean backups.
Summary
The edge comes first
VPNs, firewalls and remote access gateways are exposed by design and open onto the internal network: the most serious campaigns of autumn 2026 came through them.
A market for access
Initial access brokers steal or buy credentials, then resell the way in to ransomware affiliates. The crew that gets in is not necessarily the one that encrypts.
Patching is not enough
Inventory, prioritisation through KEV and CERT-FR, phishing-resistant MFA, compromise hunting and tested backups: all to be formalised in an EBIOS RM scenario.
Sources (16)
- Cybermalveillance.gouv.fr — Rançongiciels (ransomwares) : fiche réflexe
- ANSSI — Panorama de la cybermenace 2025 (11 mars 2026)
- Infosecurity Magazine — France: ANSSI reports ransomware attack drop in 2025
- Solutions Numériques — L'ANSSI alerte sur une cybermenace plus diffuse
- ENISA — Threat Landscape 2026 (22 septembre 2026)
- CERT-FR — CERTFR-2026-ALE-011, Citrix NetScaler ADC et Gateway
- Help Net Security — NetScaler zero-day exploitation escalates into mass attacks
- BleepingComputer — CISA orders feds to patch exploited Citrix flaws
- FBI et US Secret Service — FortiBleed Operations Continue (JCSA-20261006-01)
- CyberInsider — FortiMail zero-day exploited in attacks (CVE-2026-104286)
- CERT-FR — CERTFR-2026-ALE-009, SonicWall SMA
- The Hacker News — Bitget confirms third-party zero-day
- CISA — Known Exploited Vulnerabilities Catalog
- ANSSI — La méthode EBIOS Risk Manager, le guide
- Phinasoft — Hospital cyberattack: 5 lessons from the CNIL fine
- Phinasoft — Data breaches in the French State: Operation REACTIV
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.