FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal Credentials
FBI warns FortiBleed operators compromised over 86,000 Fortinet firewalls and VPNs to steal credentials for ransomware brokers.
The FBI and U.S. Secret Service warned on October 6, 2026 that FortiBleed operators are compromising internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. SOCRadar verified more than 86,644 affected devices across 194 countries. Attackers reuse leaked credentials, crack legacy SHA-256 hashes with Hashcat, steal session tokens, and create rogue administrator accounts that can lock out defenders. Initial-access brokers using the chain have reportedly supplied access to ransomware affiliates INC/Lynx and Payload.
- FBI and Secret Service say FortiBleed hit more than 86,644 Fortinet devices in 194 countries.
- Attackers spray leaked credentials, crack legacy SHA-256 hashes, and steal VPN session tokens.
- Operators add rogue admin accounts and sometimes lock out legitimate administrators.
- Initial-access brokers reportedly sold access to INC/Lynx and Payload ransomware affiliates.
- Agencies urge restricting management exposure, resetting credentials, and enforcing phishing-resistant MFA.
Full article498 words · extracted from gbhackers.com · click to collapse
The FBI and U.S. Secret Service issued a joint cybersecurity advisory warning that operators of “FortiBleed” continue to target internet-facing Fortinet FortiGate firewalls and SSL VPN gateways to steal credentials, maintain unauthorized access, and potentially facilitate ransomware attacks.
Published on October 6, 2026, the advisory emphasizes administrator lockouts as an emerging consequence of this campaign.
FBI Warns FortiBleed Campaign
According to the advisory, SOCRadar has verified more than 86,644 compromised devices across 194 countries.
The operation exploits reused or leaked credentials along with legacy SHA-256 password storage, allowing attackers to harvest authentication data and crack stolen hashes on a large scale.
Investigators have observed ongoing scanning of exposed Fortinet systems using previously compromised credentials.
FortiBleed’s infrastructure became apparent after its operators unintentionally exposed a backend server. The accessible directory revealed tools and datasets that support a multistage credential-harvesting and initial-access brokerage operation targeting FortiGate SSL VPN appliances.
Attackers first scan the internet for reachable VPN portals. They then conduct credential stuffing and password spraying using credentials sourced from previous Fortinet leaks and infostealer logs.
Once they compromise devices, they extract authentication artifacts, including password hashes, user databases, and session tokens.
Stolen hashes are processed through a distributed GPU cracking pipeline managed with Hashcat and Hashtopolis.
Operators enrich and validate recovered plaintext credentials, filter out potential honeypots, map victim organizations, and prioritize targets based on revenue and network structure. Working VPN configurations and target lists are then packaged for downstream buyers.
The advisory warns that attackers create additional administrative accounts to maintain access. In some cases, they delete legitimate accounts or change their passwords, making it difficult for administrators to access affected appliances while the attackers attempt lateral movement. As a result, remediation may require measures beyond routine patching and password resets.
Investigators have identified suspicious account names, including adminin, fortiAdmin, forticloud-sync, support_fortinet, system_config, and forti_support2.
Organizations should verify each account’s legitimacy rather than relying solely on username matches. The campaign also involves Active Directory enumeration and further password spraying to identify privileged accounts.
Initial-access brokers using the FortiBleed attack chain have reportedly supplied access to ransomware affiliates, including INC/Lynx and Payload.
The agencies recommend removing internet-facing administration whenever possible or restricting management access to trusted hosts and local-in policies.
Organizations should terminate administrative and VPN sessions, reset associated passwords, and enforce phishing-resistant multifactor authentication for remote-access and administrative accounts.
Defenders should compare configurations against known-good baselines, investigate any unfamiliar accounts, and review firewall, VPN, authentication, and domain controller logs. Remove unknown REST API keys, and refresh legitimate ones.
The advisory also urges administrators to implement PBKDF2 for credential storage and to eliminate weaker legacy hashes. Suspected compromises warrant isolation, evidence collection, threat hunting, and coordinated eviction. Corroborate listed IP indicators before blocking, as infrastructure addresses may be reassigned.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.