FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices

FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices

Listen to this article

0:00 —

Press play to start listening

FortiBleed attacks continue to target Fortinet FortiGate devices, with SOCRadar reporting more than 86,644 compromised devices across 194 countries.

The FBI and US Secret Service are warning about ongoing FortiBleed attacks against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways in a joint advisory (PDF) published on October 6, 2026.

Hackread.com first covered FortiBleed in June based on findings from Hudson Rock and researcher Volodymyr “Bob” Diachenko. The campaign was later linked to INC Ransom and Lynx ransomware activity, showing how exposed FortiGate access could move from credential abuse into ransomware operations.

SOCRadar has now shared additional findings with Hackread.com on the campaign’s infrastructure, credential-cracking operation and indicators.

According to the latest research, more than 86,644 devices across 194 countries have been compromised, with some victims finding themselves locked out after attackers changed passwords or removed existing accounts.

The latest advisory also identifies Payload ransomware among the groups connected to access obtained through the campaign.

How the FortiBleed Attacks Work

The campaign does not depend on a FortiOS zero-day. Attackers use credential stuffing (using stolen username-password pairs to try logging into other accounts) and password spraying (trying a few common passwords against many accounts) with credentials taken from previous Fortinet leaks and infostealer logs.

They then crack stolen password hashes offline using GPU-powered systems running Hashcat and Hashtopolis. Hashcat handles the password cracking, while Hashtopolis distributes the workload across multiple systems.

Legacy SHA-256 password storage in FortiOS made it easier for attackers to recover credentials from stolen hashes. After finding working credentials, they scan internet-facing Fortinet devices and use them to enter targeted networks.

On compromised devices, the attackers have also changed account settings. They can create new administrator accounts, delete existing ones or change passwords, leaving legitimate administrators unable to log in.

What Organizations Should Look For

SOCRadar found that the attackers use automated scripts to identify useful targets, filter out honeypots, and rank organizations based on factors such as revenue and network structure. After gaining access, they can enumerate Active Directory and look for accounts with higher privileges.

The advisory lists several suspicious administrator account names, including adminin, forticloud-tech, gttadmin, Technical_support, my_admin, forti_support2, and fgtsecure. These names should be checked against known accounts on affected FortiGate devices.

Organizations should also look at whether SSH was exposed and review REST API keys configured on the devices. An unauthorized API key can continue providing access even after passwords have been changed.

Steps for FortiGate Administrators

Resetting passwords is only one part of the cleanup. The advisory also calls for active administrator and VPN sessions to be terminated, Fortinet credentials to be reset, and management access from the internet to be restricted. Phishing-resistant multifactor authentication is recommended as an additional safeguard.

Fortinet administrators should check how their passwords are stored as well. The FBI and Secret Service recommend moving away from the older SHA-256 storage method and using PBKDF2 on supported FortiOS versions.

Where a compromise is confirmed, affected systems should be isolated and logs and other evidence reviewed before changes are made. The advisory also points organizations to CISA’s Eviction Strategies Tool for help identifying and removing the attacker’s persistence.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts