FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
FBI and Secret Service warn FortiBleed attackers continue compromising Fortinet firewalls — 86,644 devices verified — locking admins out and selling access to ransomware affiliates.
A joint FBI and U.S. Secret Service advisory says FortiBleed actors continue scanning internet-exposed FortiGate firewalls and SSL VPN gateways using credentials from prior Fortinet leak dumps and infostealer logs. SOCRadar has verified more than 86,644 compromised devices across 194 countries, and some victims are locked out when attackers delete or change original admin accounts and create new ones for persistence. The actors crack extracted password hashes on GPU clusters using Hashcat and Hashtopolis, enumerate Active Directory for privileged users, and sell access to INC/Lynx and Payload ransomware affiliates. The agencies warn recovery may require remediation beyond standard patching and password resets.
- 86,644 Fortinet devices compromised across 194 countries (SOCRadar)
- Attackers lock out admins by deleting/changing accounts and creating new ones
- Credential stuffing and spraying use leaked Fortinet dumps and infostealer logs
- Access is sold to INC/Lynx and Payload ransomware affiliates
- Recovery may require steps beyond patching and password resets
Full article299 words · extracted from helpnetsecurity.com · click to collapse
Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, according to a joint FBI and U.S. Secret Service advisory.

FortiBleed targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The advisory cites SOCRadar, which has verified more than 86,644 compromised devices in 194 countries.
“Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system,” the agencies said.
“During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment,” the advisory reads.
For affected organizations, recovery may require “remediation steps beyond standard patching and password resets.”
“Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials,” the agencies warned.
The attackers run credential stuffing and password spraying attacks using earlier Fortinet leak dumps and infostealer logs. They pull password hashes from compromised devices and crack them on a GPU cluster with Hashcat and Hashtopolis.
“Cracked credentials were enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure,” the agencies wrote.
Once inside, the attackers enumerate Active Directory accounts and look for privileged users. The group then sells the access to affiliates of the INC/Lynx and Payload ransomware groups.
The advisory also includes IP addresses used by the attackers and usernames found on victim devices, along with mitigation steps.
The FBI and the Secret Service urge victims to report incidents, though reporting in response to this advisory is voluntary, and advise against paying ransoms.
Text extracted automatically; images, tables and formatting may be missing. Original: