FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
FBI and Secret Service warn FortiBleed is still harvesting Fortinet firewall credentials, with 86,644 logins tied to ransomware access brokers.
The FBI and U.S. Secret Service warned that FortiBleed, a Russian-speaking campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, remains active. As of June 19, 2026 it had collected 86,644 working device credentials across 194 countries by stuffing and spraying leaked or infostealer passwords, then using the Go tool FortigateSniffer to capture hashes for offline GPU cracking. Attackers add new firewall administrator accounts, sometimes delete original accounts to lock victims out, and move laterally through Active Directory, Kerberos, and SMB before stealing files and session cookies. Overlaps with INC and Lynx ransomware indicate an initial-access broker is selling the access; CISA has urged phishing-resistant MFA, session termination, password resets, and PBKDF2 storage.