
The FBI and the US Secret Service warn that FortiBleed, a campaign that steals and cracks passwords for Fortinet FortiGate firewalls and SSL VPN gateways, is still active. Citing SOCRadar data, they count more than 86,644 compromised devices in 194 countries, and some victims have been locked out of their own firewalls.
What happened
On 6 October 2026 the FBI and the US Secret Service published a joint advisory on FortiBleed, a credential-theft campaign aimed at Fortinet FortiGate firewalls and SSL VPN gateways reachable from the internet. Citing the threat intelligence firm SOCRadar, the agencies put the number of compromised devices at more than 86,644 in 194 countries. The campaign is still running: the operators keep scanning exposed firewalls with credentials stolen earlier, and some victims have been locked out after the attackers deleted or changed the original accounts.
Fortinet stated in June that no new flaw in its products is involved: the attackers rely on passwords reused from earlier incidents and on brute force against weak passwords without multi-factor authentication.
How the attackers get in
According to the advisory, the operators accidentally exposed their own back-end server, revealing the whole chain: automated scanning of VPN portals, credential stuffing and password spraying fed by older Fortinet leaks and infostealer logs, then password hashes cracked offline on rented GPUs with Hashcat and Hashtopolis. Legacy SHA-256 password storage makes that cracking easier. Once inside, they create new administrator accounts (names such as forticloud-sync, fortiAdmin or adminsslvpn are listed), enumerate Active Directory and resell the access. Ransomware affiliates, including INC/Lynx and Payload, have used it.
What to do now
- Take administration off the internet, or at least restrict it with trusted hosts or a local-in policy.
- Close all admin and VPN sessions, then reset every VPN and administrator password.
- Enforce phishing-resistant MFA on the VPN and on every administrative interface.
- Audit the accounts with
show system adminand compare the configuration with a known-good backup; remove any account you do not recognise. - Review REST API keys (
show system api-user): delete unknown ones, regenerate the others. - Switch to PBKDF2: on FortiOS 7.2.11, 7.4.8, 7.6.1 or later, reset administrator passwords, then under
config system password-policyrunset login-lockout-upon-weaker-encryption enable(login-lockout-upon-downgradeon 7.2 and 7.4). Fortinet recommends the latest 7.4, 7.6 or 8.0 releases. - Search firewall, VPN and domain controller logs for the IP addresses listed in the advisory.
Our take
No patch fixes FortiBleed: a firewall whose administration page faces the internet, protected by a password alone, is an open door. An edge device deserves the same care as a domain controller: no public admin interface, MFA everywhere and a regular check of its account list.
Sources
- FBI / USSS — FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts (JCSA-20261006-01)
- Fortinet PSIRT — Analysis of reported credential compromise of FortiGate devices
- Fortinet Community — Enforcing PBKDF2 as hash function for administrator accounts in FortiOS v7.2.11 and later
- The Hacker News — FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
How we choose, verify and write our analyses →
Stolen logins often start with a phishing message. Received a suspicious SMS or email? Check it before you click:
Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.
Talk to an expert Our managed server services →

