FortiBleed Attack Campaign Exploiting Fortinet Firewalls and VPNs – FBI Warns
FBI warns FortiBleed compromised over 86,000 Fortinet firewalls and VPNs in 194 countries.
The FBI and U.S. Secret Service warned that the ongoing FortiBleed campaign is compromising internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, reportedly affecting more than 86,644 devices across 194 countries. It is not a single new Fortinet vulnerability: operators reuse leaked or weak credentials, crack legacy SHA-256 hashes, and sell verified access. After entry they may create administrator accounts, disable or delete legitimate admins, and enumerate Active Directory. The advisory links the activity to initial-access brokers supporting INC/Lynx and Payload ransomware.
- More than 86,644 FortiGate and SSL VPN devices in 194 countries affected.
- Attackers spray, stuff, and crack legacy SHA-256 password hashes.
- They create admin accounts and can lock out legitimate administrators.
- Access brokers are linked to INC/Lynx and Payload ransomware.
- FBI urges MFA, PBKDF2 hashes, and restricted management exposure.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 103.27.186.156 | ll, VPN, proxy, and DNS connections. Proxy 154.202.59.169 , 103.27.186.156 Check for connections to attacker relay infrastructure. Bea |
| ipv4 | 104.28.155.27 | to the FortiBleed attack chain. Brute Force / Login Sources 104.28.155.27 , 185.136.15.43 , 185.136.15.66 , 193.8.186.33 , 45.227.254 |
| ipv4 | 154.202.59.169 | nvestigate firewall, VPN, proxy, and DNS connections. Proxy 154.202.59.169 , 103.27.186.156 Check for connections to attacker relay in |
| ipv4 | 185.136.15.43 | d attack chain. Brute Force / Login Sources 104.28.155.27 , 185.136.15.43 , 185.136.15.66 , 193.8.186.33 , 45.227.254.210 , 77.91.118 |
| ipv4 | 185.136.15.66 | Brute Force / Login Sources 104.28.155.27 , 185.136.15.43 , 185.136.15.66 , 193.8.186.33 , 45.227.254.210 , 77.91.118.10 , 80.75.212. |
| ipv4 | 185.199.199.56 | n Sources 87.251.64.13 , .16 , .17 , .44 , 66.175.220.111 , 185.199.199.56 Check authentication activity and compromised accounts. Sus |
| ipv4 |
Full article727 words · extracted from cybersecuritynews.com · click to collapse
The FBI and U.S. Secret Service have issued a joint cybersecurity advisory warning that the ongoing FortiBleed campaign is targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways worldwide.
The credential-compromise operation has reportedly affected more than 86,644 devices across 194 countries, creating a major risk for organizations that expose Fortinet management or remote-access services to the internet.
FortiBleed is not described as a single newly disclosed Fortinet vulnerability. Instead, attackers reportedly abuse reused, leaked, or weak credentials to access FortiGate appliances.
The campaign also exploits legacy SHA-256 password storage, allowing stolen authentication data to be processed through distributed password-cracking infrastructure.
Investigators said the operation became visible after its operators accidentally exposed a backend server containing tools, target data, and workflows.
FortiBleed Campaign Exploits
The exposed infrastructure reportedly showed an organized access-broker operation that scanned for publicly reachable FortiGate SSL VPN portals, tested stolen passwords, cracked password hashes, and verified accounts before selling working access to other cybercriminals.
The attackers allegedly used credential stuffing and password spraying to test credentials obtained from previous data leaks and infostealer logs.
After gaining entry, they may create new FortiGate administrator accounts to retain access. They can then enumerate Active Directory users, identify privileged accounts, and attempt lateral movement inside victim networks.
A key concern is that some affected organizations may lose access to their own Fortinet devices. The advisory said threat actors have changed passwords, disabled accounts, or deleted legitimate administrator accounts after creating their own persistent accounts.
FortiBleed MITRE ATT&CK Techniques :
| Tactic | Technique | MITRE ID |
|---|---|---|
| Reconnaissance | Active Scanning | T1595 |
| Initial Access | Exploit Public-Facing Application | T1190 |
| Credential Access | Password Spraying | T1110.003 |
| Credential Access | Credential Stuffing | T1110.004 |
| Credential Access | Credential Dumping | T1003 |
| Credential Access | Password Cracking | T1110.002 |
| Persistence | Create Local Account | T1136.001 |
| Defense Evasion / Initial Access | Valid Accounts | T1078 |
| Discovery | Account Discovery | T1087 |
| Exfiltration | Exfiltration Over C2 Channel | T1041 |
| Impact | Account Access Removal | T1531 |
This tactic can delay incident response and leave defenders locked out while attackers continue operating in the environment. The FBI and USSS also warned that FortiBleed activity has been linked to initial-access brokers supporting ransomware operations.
Reported downstream ransomware connections include INC/Lynx and Payload ransomware, meaning a compromised firewall or VPN gateway could become the first stage of a larger enterprise-wide intrusion.
Organizations should immediately review all Fortinet administrative and VPN accounts, particularly unfamiliar accounts such as forticloud-sync, fgtsecure, forti_support2, or Technical_support.
Security teams should also investigate unexpected REST API keys, configuration changes, suspicious authentication activity, and connections involving known malicious infrastructure identified in the advisory.
The agencies recommend restricting external management access through trusted hosts or local-in policies, and removing internet-based administration where possible.
Administrators should terminate active administrative and VPN sessions, reset all Fortinet VPN and administrator credentials, and enforce phishing-resistant multifactor authentication for remote access and management interfaces.
Organizations running FortiOS should also verify that administrator credentials use PBKDF2 rather than weaker legacy hashing methods. Review firewall, VPN, authentication, and domain-controller logs to identify unauthorized accounts, successful suspicious logins, lateral movement, and attempts to alter device configurations.
Indicators of Compromise
| IOC Type | Indicator | Key Detection Point |
|---|---|---|
| C2 | 45.154.12.132 | Investigate firewall, VPN, proxy, and DNS connections. |
| Proxy | 154.202.59.169, 103.27.186.156 | Check for connections to attacker relay infrastructure. |
| Beacon Relay | 45.155.250.158 | Hunt HTTPS traffic on ports 4332 and 4432. |
| Password Cracking | 85.11.187.8 | Associated with FortiBleed password-cracking activity. |
| Related Infrastructure | 193.8.187.2, 193.8.187.42 | Linked to the FortiBleed attack chain. |
| Brute Force / Login Sources | 104.28.155.27, 185.136.15.43, 185.136.15.66, 193.8.186.33, 45.227.254.210, 77.91.118.10, 80.75.212.113 | Hunt for brute-force attempts and compromised logins. |
| Brute Force / Login Sources | 87.251.64.13, .16, .17, .44, 66.175.220.111, 185.199.199.56 | Check authentication activity and compromised accounts. |
| Suspicious Accounts | forticloud-sync, forticloud-tech, fgtsecure, fgtsec, forti_support2, support_fortinet | Check for unauthorized persistence accounts. |
| Network Behavior | Ports 4332, 4432 | Investigate unusual HTTPS traffic. |
| Device Changes | New admin accounts, password changes, unknown API keys | Review for persistence and unauthorized access. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.