FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
FBI says ongoing FortiBleed attacks still lock FortiGate VPN admins out using leaked and cracked credentials.
The FBI warned that FortiBleed attacks remain active against exposed Fortinet FortiGate firewalls and SSL VPN gateways, with intruders locking out legitimate administrators. Attackers use previously leaked credentials, infostealer logs, credential stuffing, and password spraying, then crack stolen hashes offline with a distributed GPU cluster running Hashcat and Hashtopolis. A June exposure contained usernames and plaintext passwords for 73,932 firewall URLs in 194 countries; SOCRadar later counted 86,644 compromised devices and tied the activity to INC/Lynx and Payload ransomware affiliates. The FBI said actors create new admin accounts, delete or reset existing ones, persist, move laterally, and package VPN access for sale, and advised MFA, session termination, log review, and PBKDF2 password storage.