FBI: FortiBleed Has Compromised 86,000 Firewalls

The FBI and U.S. Secret Service issued a joint advisory on October 6 warning that FortiBleed — a credential-harvesting campaign targeting Fortinet FortiGate firewalls and SSL VPN gateways — remains active months after its initial discovery. With more than 86,000 confirmed device compromises across 194 countries and direct links to ransomware operations, FortiBleed has become one of the most significant infrastructure-level campaigns of 2026.

What Is FortiBleed?

FortiBleed first surfaced in June 2026 when researchers at SOCRadar and Hudson Rock documented a large-scale operation targeting internet-exposed Fortinet appliances. Rather than exploiting a software vulnerability in the traditional sense, FortiBleed relies on a disturbingly effective combination of stolen credentials, credential stuffing, and passive traffic interception to compromise firewalls at scale.

The campaign is attributed to a Russian-speaking, financially motivated group operating as an initial access broker — an outfit that packages and sells network footholds to downstream attackers, including ransomware operators.

How the Attack Works

The FortiBleed operation follows a methodical five-stage chain that security researchers have mapped out in detail.

First, attackers scan the internet for exposed FortiGate management portals and SSL VPN login pages. Once targets are identified, they attempt to log in using credentials sourced from data-breach dumps and infostealer malware logs through credential stuffing and password spraying.

Once inside a device, the attackers deploy a custom Go-based tool called FortigateSniffer, which passively intercepts authentication traffic across 24 different protocols. This tool harvests additional credentials and password hashes from the network traffic flowing through the compromised firewall — turning a perimeter security device into a credential collection point.

The captured password hashes — many stored using Fortinet’s legacy SHA-256 format — are then routed to a GPU-accelerated cracking cluster running Hashcat and Hashtopolis for offline brute-forcing. Once cracked, the credentials enable lateral movement, Active Directory enumeration, Kerberos validation, and SMB authentication across the victim’s internal network.

What makes FortiBleed particularly dangerous is its sophistication in target selection. The operators filter out honeypots, map victim organizations, and prioritize targets by revenue and network structure. They are not carpet-bombing indiscriminately — they are triaging for high-value access.

Locked Out of Your Own Firewall

The most operationally devastating element of FortiBleed is the admin lockout. In many confirmed incidents, attackers create rogue administrator accounts on the compromised firewall, then delete the legitimate admin accounts or change their passwords. This leaves organizations locked out of their own security infrastructure.

Security firm Huntress has warned that in some cases, victims may need to perform full factory resets and device rebuilds to regain control — a process that takes critical perimeter defenses offline during an active intrusion. The commonly observed rogue account names include variations like adminin, fortiAdmin, forticloud-sync, fgtsecure, Technical_support, and support_fortinet, among others.

The Ransomware Connection

FortiBleed is not a standalone operation. In July 2026, SOCRadar linked the campaign to the INC/Lynx and Payload ransomware groups after discovering negotiation panels belonging to both groups on servers used in the FortiBleed infrastructure. The FBI advisory confirmed these links, noting that FortiBleed-compromised access has served as an entry point for ransomware affiliates.

SOCRadar has confirmed at least 12 ransomware deployments originating from FortiBleed access, resulting in the encryption of hundreds of endpoints. The stolen session cookies also give attackers persistent access that survives credential resets, meaning even organizations that change their passwords may not fully sever the attackers’ foothold.

Scale of the Compromise

The numbers are staggering. SOCRadar’s latest count puts confirmed device compromises at 86,644 across 194 countries. Critically, this figure represents confirmed compromises — devices where the attackers obtained working credentials — not merely exposed devices. When a server used in the operation was briefly exposed in June, it revealed 73,932 firewall URLs with associated plaintext passwords, along with working VPN configurations and organized target lists ready for sale.

SOCRadar emphasized that devices breached months ago remain in the attackers’ validated inventory, meaning that organizations compromised early in the campaign may still be at risk even if they have not seen recent scanning activity.

Why Patching Alone Is Not Enough

The FBI advisory pointedly warns that patching and resetting Fortinet passwords may not be sufficient. Because FortiBleed exploits reused or leaked credentials rather than a single software flaw, there is no single patch that closes the door. Attackers continue scanning with previously obtained credentials, and the stolen session cookies and configuration files provide avenues for re-entry.

The legacy SHA-256 password hashing used by older FortiOS configurations is a particular weak point. Compared to modern alternatives like PBKDF2, SHA-256 hashes can be cracked orders of magnitude faster on GPU hardware, giving attackers a realistic path from intercepted hashes to working passwords.

What Organizations Should Do Now

The FBI, CISA, and multiple security firms have converged on a consistent set of remediation steps for any organization running FortiGate appliances:

  • Restrict external management access. Remove internet-facing admin interfaces immediately.
  • Terminate all active VPN and administrative sessions to sever any existing attacker connections.
  • Reset all VPN and administrative passwords and switch credential storage to PBKDF2 rather than legacy SHA-256.
  • Enforce phishing-resistant multi-factor authentication on all remote access and administrative accounts.
  • Audit for unauthorized accounts. Review all local and API accounts for unknown entries, particularly those matching the rogue account naming patterns documented in the advisory.
  • Review logs for suspicious activity, including unauthorized configuration changes, new account creation, and unusual authentication patterns.
  • Investigate downstream. Do not stop at the firewall. Check for lateral movement, data exfiltration, and signs of ransomware staging within the broader network.
  • Set up out-of-band console access as a recovery path in case admin accounts are compromised or deleted.

What to Watch Next

FortiBleed underscores a persistent truth in enterprise security: perimeter devices are high-value targets, and credential hygiene remains the most neglected defensive basic. The fact that attackers can compromise nearly 87,000 firewalls across 194 countries using reused passwords and legacy hashing — without needing a single zero-day — is a sobering indictment of how many organizations treat credential management as an afterthought.

With the FBI confirming that the campaign remains active as of this week and at least three ransomware groups feeding off the access it generates, FortiBleed is not a historical incident to study — it is an ongoing emergency. Organizations running Fortinet infrastructure should treat the joint advisory as a starting gun for immediate investigation, not a memo to file for the next security review.

Sources: FBI/USSS Joint Advisory (IC3), The Hacker News, BleepingComputer, SOCRadar

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.