FBI, Secret Service add to warnings of FortiBleed credential stealing campaign
FBI and Secret Service say FortiBleed compromised over 86,000 Fortinet firewalls in 194 countries.
The FBI and Secret Service warned that the ongoing FortiBleed campaign has compromised more than 86,000 internet-facing Fortinet FortiGate firewalls and VPN gateways across 194 countries using reused or leaked credentials. Operators scanned exposed SSL VPN portals, ran credential stuffing and password spraying, validated stolen logins, and created new accounts on firewalls. Initial access brokers offered that access to ransomware affiliates tied to INC/Lynx and Payload, and at least 12 organizations were encrypted. CISA and UK officials had warned earlier, and Russian operators were alleged to have used the campaign against UK government email.