Cyber Security News

FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal Credentials

The FBI and U.S. Secret Service issued a joint cybersecurity advisory warning that operators of “FortiBleed” continue to target internet-facing Fortinet FortiGate firewalls and SSL VPN gateways to steal credentials, maintain unauthorized access, and potentially facilitate ransomware attacks.

Published on October 6, 2026, the advisory emphasizes administrator lockouts as an emerging consequence of this campaign.

FBI Warns FortiBleed Campaign

According to the advisory, SOCRadar has verified more than 86,644 compromised devices across 194 countries.

The operation exploits reused or leaked credentials along with legacy SHA-256 password storage, allowing attackers to harvest authentication data and crack stolen hashes on a large scale.

Investigators have observed ongoing scanning of exposed Fortinet systems using previously compromised credentials.

FortiBleed’s infrastructure became apparent after its operators unintentionally exposed a backend server. The accessible directory revealed tools and datasets that support a multistage credential-harvesting and initial-access brokerage operation targeting FortiGate SSL VPN appliances.

Attackers first scan the internet for reachable VPN portals. They then conduct credential stuffing and password spraying using credentials sourced from previous Fortinet leaks and infostealer logs.

Once they compromise devices, they extract authentication artifacts, including password hashes, user databases, and session tokens.

Stolen hashes are processed through a distributed GPU cracking pipeline managed with Hashcat and Hashtopolis.

Operators enrich and validate recovered plaintext credentials, filter out potential honeypots, map victim organizations, and prioritize targets based on revenue and network structure. Working VPN configurations and target lists are then packaged for downstream buyers.

The advisory warns that attackers create additional administrative accounts to maintain access. In some cases, they delete legitimate accounts or change their passwords, making it difficult for administrators to access affected appliances while the attackers attempt lateral movement. As a result, remediation may require measures beyond routine patching and password resets.

Investigators have identified suspicious account names, including adminin, fortiAdmin, forticloud-sync, support_fortinet, system_config, and forti_support2.

Organizations should verify each account’s legitimacy rather than relying solely on username matches. The campaign also involves Active Directory enumeration and further password spraying to identify privileged accounts.

Initial-access brokers using the FortiBleed attack chain have reportedly supplied access to ransomware affiliates, including INC/Lynx and Payload.

The agencies recommend removing internet-facing administration whenever possible or restricting management access to trusted hosts and local-in policies.

Organizations should terminate administrative and VPN sessions, reset associated passwords, and enforce phishing-resistant multifactor authentication for remote-access and administrative accounts.

Defenders should compare configurations against known-good baselines, investigate any unfamiliar accounts, and review firewall, VPN, authentication, and domain controller logs. Remove unknown REST API keys, and refresh legitimate ones.

The advisory also urges administrators to implement PBKDF2 for credential storage and to eliminate weaker legacy hashes. Suspected compromises warrant isolation, evidence collection, threat hunting, and coordinated eviction. Corroborate listed IP indicators before blocking, as infrastructure addresses may be reassigned.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

24 minutes ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

40 minutes ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

52 minutes ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

2 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

3 hours ago

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…

3 hours ago