Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
FBI and Secret Service say FortiBleed still compromises Fortinet VPNs, locking out owners and enabling ransomware affiliates.
The FBI and U.S. Secret Service warned that FortiBleed, a credential-compromise campaign against Fortinet firewalls and VPN gateways, remains active. Attackers use stolen credentials to reach exposed devices, create administrator accounts, and change or disable passwords so legitimate owners are locked out. SOCRadar previously verified 86,644 compromised devices across 194 countries and later estimated 400,000 to 450,000 firewalls were targeted. The alert says initial access brokers are providing that access to ransomware affiliates, including INC/Lynx and Payload.
- FBI and Secret Service say FortiBleed remains an active Fortinet credential campaign.
- SOCRadar later estimated 400,000 to 450,000 firewalls targeted after 86,644 compromised devices.
- Stolen credentials let attackers create admin accounts and lock legitimate owners out.
- Initial access brokers supply access to ransomware affiliates INC/Lynx and Payload.
Full article603 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The FBI and Secret Service warned Fortinet users that FortiBleed, uncovered this summer, is a continuing threat.
Listen to this article
0:00
Learn more.
FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday.
“Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the alert states. “In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.”
When it was first uncovered earlier this year, SOCRadar verified more than 86,644 compromised devices across 194 countries. Ensar Seker, chief information security officer of the company, told CyberScoop that “in our later investigation, we identified more than 400,000 or 450,000 firewalls targeted by the wider operation.”
There are different aspects of the operation that make comparisons imprecise over time, but overall the numbers “show the campaign is broader and more serious than we understood at the beginning,” Seker said.
The attackers can disable accounts or change passwords to lock users out with the access they gain, making standard password resets and patching insufficient, the government alert reads.
The alert also warns that initial access brokers are making use of the FortiBleed attack to provide access to ransomware affiliates, including INC/Lynx and Payload.
The government warning provides additional confirmation about the most worrisome elements of FortiBleed, Seker said.
“What stands out for me is that FortiBleed is still an active threat, and attackers are using stolen credentials to access the exposed Fortinet devices, create new administration accounts, and in some cases, lock the real owners out,” he said. “The FBI and the Secret Service also confirm that the success can lead to ransomware attacks as well.”
The FBI and Secret Service recommend that Fortinet customers restrict external management or remove internet administration entirely, reset credentials, set up multifactor authentication, review firewall and VPN users for unauthorized changes, review logs for potential lateral movement, and enable secure credential storage.
The agencies are seeking any information and indicators of compromise that organizations can share, including IP addresses and any usernames the attackers use.
Latest Podcasts
Government
Here’s how experts think CISA should tell agencies to protect OT
The legal questions raised by agentic AI hacks
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
Technology
Threats
AI policy circles targeted in China-linked phishing operation
WaterISAC reckons with range of threats after summer of cyberattacks
Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Policy
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack