FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away
FBI and Secret Service say FortiBleed credential campaign compromised 86,644 Fortinet FortiGate firewalls across 194 countries, selling access to ransomware affiliates.
The FBI and U.S. Secret Service issued a joint advisory on FortiBleed, a credential-harvesting campaign that has compromised 86,644 Fortinet FortiGate devices across 194 countries per SOCRadar verification. Attackers scan for exposed SSL VPN portals, run credential stuffing and password spraying with leaked credentials and infostealer logs, and crack harvested hashes on GPU clusters using Hashcat and Hashtopolis. Victims face lockout as actors delete or change admin passwords and create rogue accounts; stolen access is sold to initial access brokers serving INC/Lynx and Payload ransomware affiliates. Mitigations include removing internet-facing administration, resetting credentials, phishing-resistant MFA, and migrating legacy SHA-256 password storage to PBKDF2 on FortiOS 7.2.11 and later.