FortiBleed: the FBI warns attackers are still logging into exposed FortiGate firewalls with stolen passwords

The FBI and the US Secret Service warn that FortiBleed, a campaign that steals and cracks passwords for Fortinet FortiGate firewalls and SSL VPN gateways, is still active. Citing SOCRadar data, they count more than 86,644 compromised devices in 194 countries, and some victims have been locked out of their own firewalls.

What happened

On 6 October 2026 the FBI and the US Secret Service published a joint advisory on FortiBleed, a credential-theft campaign aimed at Fortinet FortiGate firewalls and SSL VPN gateways reachable from the internet. Citing the threat intelligence firm SOCRadar, the agencies put the number of compromised devices at more than 86,644 in 194 countries. The campaign is still running: the operators keep scanning exposed firewalls with credentials stolen earlier, and some victims have been locked out after the attackers deleted or changed the original accounts.

Fortinet stated in June that no new flaw in its products is involved: the attackers rely on passwords reused from earlier incidents and on brute force against weak passwords without multi-factor authentication.

How the attackers get in

According to the advisory, the operators accidentally exposed their own back-end server, revealing the whole chain: automated scanning of VPN portals, credential stuffing and password spraying fed by older Fortinet leaks and infostealer logs, then password hashes cracked offline on rented GPUs with Hashcat and Hashtopolis. Legacy SHA-256 password storage makes that cracking easier. Once inside, they create new administrator accounts (names such as forticloud-sync, fortiAdmin or adminsslvpn are listed), enumerate Active Directory and resell the access. Ransomware affiliates, including INC/Lynx and Payload, have used it.

What to do now

  1. Take administration off the internet, or at least restrict it with trusted hosts or a local-in policy.
  2. Close all admin and VPN sessions, then reset every VPN and administrator password.
  3. Enforce phishing-resistant MFA on the VPN and on every administrative interface.
  4. Audit the accounts with show system admin and compare the configuration with a known-good backup; remove any account you do not recognise.
  5. Review REST API keys (show system api-user): delete unknown ones, regenerate the others.
  6. Switch to PBKDF2: on FortiOS 7.2.11, 7.4.8, 7.6.1 or later, reset administrator passwords, then under config system password-policy run set login-lockout-upon-weaker-encryption enable (login-lockout-upon-downgrade on 7.2 and 7.4). Fortinet recommends the latest 7.4, 7.6 or 8.0 releases.
  7. Search firewall, VPN and domain controller logs for the IP addresses listed in the advisory.

Our take

No patch fixes FortiBleed: a firewall whose administration page faces the internet, protected by a password alone, is an open door. An edge device deserves the same care as a domain controller: no public admin interface, MFA everywhere and a regular check of its account list.

Sources

How we choose, verify and write our analyses →

Stolen logins often start with a phishing message. Received a suspicious SMS or email? Check it before you click:

Check an SMS Check an email

Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.

Talk to an expert Our managed server services →