FBI and Secret Service Say FortiBleed Still Locks Out Fortinet Admins
FBI and Secret Service warn FortiBleed compromised about 86,644 Fortinet devices in 194 countries and fed ransomware affiliates.
On October 6, 2026, the FBI and U.S. Secret Service warned that FortiBleed remains an active credential campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways and is not a single new Fortinet vulnerability. Most outlets cite SOCRadar’s 86,644 compromised devices across 194 countries, variously as exact, more than 86,644, more than 86,000, or about 86,644, while CSO Online says more than 80,000 worldwide; The Hacker News dates 86,644 working credentials to June 19, 2026, BleepingComputer cites a June exposure of usernames and plaintext passwords for 73,932 firewall URLs, and CyberScoop says SOCRadar later estimated 400,000 to 450,000 firewalls were targeted. Attackers reuse leaked dumps and infostealer logs through credential stuffing and password spraying—SecurityWeek also says brute-force—and crack legacy SHA-256 hashes offline with Hashcat and Hashtopolis on GPUs, with The Hacker News also naming FortigateSniffer and CSO Online referring to rented GPUs. They then create administrator accounts, change, disable, or delete legitimate accounts to lock owners out, steal session tokens, enumerate Active Directory, move laterally, and sell access; most reports name INC/Lynx and Payload, The Hacker News mentions only INC and Lynx, and The Record says at least 12 organizations were encrypted. The Hacker News describes a Russian-speaking campaign, SecurityWeek a Russian initial-access broker, and The Record alleges use against UK government email after earlier CISA and UK warnings. CSO Online adds that investigators examined backend infrastructure, found command-and-control servers, relays, and scanning hosts, and published account names and IP indicators; agencies urge restricted management exposure, session termination, credential resets, phishing-resistant MFA, log review, and PBKDF2 storage, and Help Net Security says recovery may exceed ordinary patching and resets.
- On October 6, 2026, the FBI and U.S. Secret Service warned that FortiBleed remains active against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways and is not a single new vulnerability.
- SOCRadar-linked counts center on 86,644 compromised devices in 194 countries; outlets also say more than 86,644, more than 86,000, about 86,644, or more than 80,000, while BleepingComputer cites a June exposure of 73,932 firewall URLs and…
- Attackers reuse leaked Fortinet dumps and infostealer logs through stuffing and spraying—SecurityWeek also says brute-force—and crack legacy SHA-256 hashes offline with Hashcat, Hashtopolis, and GPUs; The Hacker News also names the Go tool…
- Intruders create administrator accounts and change, disable, or delete legitimate accounts to lock owners out, steal session tokens, enumerate Active Directory, and move laterally.
- Most reports say access was sold to INC/Lynx and Payload ransomware affiliates; The Hacker News names only INC and Lynx, and The Record says at least 12 organizations were encrypted.
- CSO Online says investigators examined backend infrastructure, found command-and-control servers, relays, and scanning hosts, and published account names and IP indicators.
- Agencies urge restricted internet administration, session termination, credential resets, phishing-resistant MFA, log review, and PBKDF2 storage; Help Net Security says recovery may require more than patching and password resets.
Coverage timelineoldest first · each row is one article
- · 2d agoAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
CyberScoop· 83
FBI and Secret Service say FortiBleed still compromises Fortinet VPNs, locking out owners and enabling ransomware affiliates.
- · 1d agoFortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
The Register · Security· 80
FBI and Secret Service confirm ongoing FortiBleed attacks on 86,644 Fortinet devices across 194 countries, with INC/Lynx and Payload ransomware affiliates using stolen access.
- · 1d ago