FBI and Secret Service Warn of FortiBleed Lockout Threat

LowInfosecurity Magazine·

At a glance

Severity
Low
Used in attacks
No flaws named
Reported by
1 outlet

US cybersecurity authorities have urged administrators of Fortinet firewalls and gateways to harden their devices after revealing that the FortiBleed campaign is still ongoing.

A warning notice published by the FBI and US Secret Service on October 6 cited SOCRadar figures that FortiBleed has already compromised 86,644 devices across 194 countries.

The campaign targets Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. Ransomware affiliates from INC, Lynx and Payload groups are among those using the compromised credentials stolen in FortiBleed attacks for initial access, it claimed.

“Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials,” the notice read. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets.”

Read more on credential compromise: Researchers Track 2.9 Billion Compromised Credentials.

The campaign was first revealed back in June, after a security researcher discovered a trove of Fortinet usernames and plaintext passwords.

Hackers use automated tools to scan for exposed FortiGate SSL VPN portals, and then employ credential stuffing and password spraying techniques based on prior Fortinet leak dumps and infostealer logs to gain access.

Once they have found and exfiltrated additional credentials, they use a “GPU-accelerated cracking cluster” running Hashcat and Hashtopolis in order to decrypt the passwords into plaintext, the notice explained.

“Cracked credentials were enriched, sorted and validated, with scripts filtering out honeypots, mapping organizations and prioritizing high-value targets based on revenue and network structure. New administrative accounts were created on the firewall to maintain persistence,” the noticed continued.

“With verified credentials in hand, attackers moved into victim environments, conducting Active Directory enumeration and password spraying to expand access and identify privileged accounts.”

Incident Response and Mitigation Advice

The FBI/Secret Service notice urged organizations that detect potential compromise to:

  • Isolate compromised hosts by quarantining or taking them offline
  • Perform threat hunting to scope the intrusion
  • Report the compromise to the FBI or Secret Service
  • Use CISA’s Eviction Strategies Tool to evict the threat actor
  • Harden the network by locking down management access
  • Terminate admin/VPN sessions and reset credentials
  • Enable phishing-resistant MFA
  • Review firewall and VPN users and other configurations for unauthorized changes
  • Review firewall, VPN, authentication, and domain controller logs for lateral movement
  • Ensure secure credential storage using the PBKDF2 algorithm

John Strand, owner of Black Hills Information Security, said the most concerning thing about FortiBleed is the silent persistence it grants to threat actors.

“I’m not nearly as worried about an attacker who gets into an organization, locks everything down, and announces their presence,” he said. “I’m terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access.”

Originally published by Infosecurity Magazine. © Infosecurity Magazine.

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. Infosecurity Magazine ↗Established SourceFirst reported

    2026-10-08 08:40 UTC

Related stories