The FBI and U.S. Secret Service are warning that the ongoing FortiBleed credential-compromise campaign has affected more than 86,644 Fortinet devices across 194 countries, according to a new joint cybersecurity advisory.
The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways, using credentials obtained from previous Fortinet leaks and infostealer logs along with password spraying and credential stuffing. Stolen password hashes are sent to a distributed GPU cluster where attackers attempt to crack them and convert the data into usable credentials.
After gaining access, attackers create new administrative accounts to maintain persistence and can move further into victim networks by enumerating Active Directory accounts and searching for privileged credentials. In some incidents, attackers have changed passwords or deleted legitimate accounts, locking organizations out of their own Fortinet devices and requiring remediation beyond standard patching and password resets.
The FBI and Secret Service said the operation ultimately packages and sells working VPN configurations and access to compromised networks to other threat actors. The FortiBleed attack chain has already been observed providing initial access to ransomware affiliates, including INC/Lynx and Payload ransomware.
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“FortiBleed is a good example of why organizations can’t treat perimeter security appliances as ‘set it and forget it’ infrastructure. Firewalls and VPN gateways are high-value targets because compromising one can give an attacker a trusted entry point into the network.
“What makes this campaign particularly concerning is that organizations may be dealing with more than a vulnerability that needs to be patched. If attackers have valid credentials or have already created new administrative accounts, applying an update and changing a password may not remove them from the environment. Defenders need to assume that previously exposed devices could already be compromised and investigate accordingly.
“Organizations should review administrative accounts, authentication logs and configuration changes, rotate potentially exposed credentials, enforce MFA wherever possible, restrict management interfaces from the public internet and look for evidence of lateral movement. If privileged credentials were accessible from the compromised environment, those credentials should also be considered potentially exposed.
“The ransomware connection also shows how mature the cybercrime ecosystem has become. The people gaining access don’t necessarily have to be the ones deploying ransomware. Initial access itself has value, and compromised VPN access can be packaged and sold to another criminal group that takes the attack from there.”
John Strand, Owner, Black Hills Information Security, Inc.:
“The most interesting thing to me about this particular attack is that some of these attackers are actually selling access to compromised networks to other threat actors. It’s basically malicious hacking as a service. And that concerns me because this isn’t necessarily a ransomware-style attack. You’re getting much closer to what we traditionally think of as an advanced persistent threat, and the persistence is what scares me. I’m not nearly as worried about an attacker who gets into an organization, locks everything down, and announces their presence. I’m terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access.”
If you haven’t addressed FortiBleed, you should have an incentive to do it now. If you have addressed FortiBleed, congratulations. Now do again as it is better to be safe than sorry.
Related
This entry was posted on October 7, 2026 at 4:37 pm and is filed under Commentary with tags FBI, Secret Service. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
FBI, Secret Service warn FortiBleed campaign has compromised 86,000+ devices
The FBI and U.S. Secret Service are warning that the ongoing FortiBleed credential-compromise campaign has affected more than 86,644 Fortinet devices across 194 countries, according to a new joint cybersecurity advisory.
The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways, using credentials obtained from previous Fortinet leaks and infostealer logs along with password spraying and credential stuffing. Stolen password hashes are sent to a distributed GPU cluster where attackers attempt to crack them and convert the data into usable credentials.
After gaining access, attackers create new administrative accounts to maintain persistence and can move further into victim networks by enumerating Active Directory accounts and searching for privileged credentials. In some incidents, attackers have changed passwords or deleted legitimate accounts, locking organizations out of their own Fortinet devices and requiring remediation beyond standard patching and password resets.
The FBI and Secret Service said the operation ultimately packages and sells working VPN configurations and access to compromised networks to other threat actors. The FortiBleed attack chain has already been observed providing initial access to ransomware affiliates, including INC/Lynx and Payload ransomware.
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“FortiBleed is a good example of why organizations can’t treat perimeter security appliances as ‘set it and forget it’ infrastructure. Firewalls and VPN gateways are high-value targets because compromising one can give an attacker a trusted entry point into the network.
“What makes this campaign particularly concerning is that organizations may be dealing with more than a vulnerability that needs to be patched. If attackers have valid credentials or have already created new administrative accounts, applying an update and changing a password may not remove them from the environment. Defenders need to assume that previously exposed devices could already be compromised and investigate accordingly.
“Organizations should review administrative accounts, authentication logs and configuration changes, rotate potentially exposed credentials, enforce MFA wherever possible, restrict management interfaces from the public internet and look for evidence of lateral movement. If privileged credentials were accessible from the compromised environment, those credentials should also be considered potentially exposed.
“The ransomware connection also shows how mature the cybercrime ecosystem has become. The people gaining access don’t necessarily have to be the ones deploying ransomware. Initial access itself has value, and compromised VPN access can be packaged and sold to another criminal group that takes the attack from there.”
John Strand, Owner, Black Hills Information Security, Inc.:
“The most interesting thing to me about this particular attack is that some of these attackers are actually selling access to compromised networks to other threat actors. It’s basically malicious hacking as a service. And that concerns me because this isn’t necessarily a ransomware-style attack. You’re getting much closer to what we traditionally think of as an advanced persistent threat, and the persistence is what scares me. I’m not nearly as worried about an attacker who gets into an organization, locks everything down, and announces their presence. I’m terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access.”
If you haven’t addressed FortiBleed, you should have an incentive to do it now. If you have addressed FortiBleed, congratulations. Now do again as it is better to be safe than sorry.
Share this:
Like this:
Related
This entry was posted on October 7, 2026 at 4:37 pm and is filed under Commentary with tags FBI, Secret Service. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.