FBI: FortiBleed attackers can lock organizations out of their own firewalls
FBI says FortiBleed operators hit over 80,000 FortiGate devices and can lock victims out of firewalls.
The FBI and U.S. Secret Service examined backend infrastructure behind the ongoing FortiBleed campaign, which has already affected more than 80,000 devices worldwide. Operators stole Fortinet credentials, cracked password hashes offline with rented GPUs, Hashcat, and Hashtopolic, then created administrative accounts on FortiGate firewalls and sometimes deleted legitimate accounts to lock organizations out. The FBI said attackers enumerated Active Directory, moved laterally with stolen credentials, and offered access to ransomware affiliates including INC/Lynx and Payload. Investigators also found command-and-control servers, relays, and scanning hosts, and published account names and IP indicators.