"Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," the FBI and US Secret Service warned in a joint advisory.
Federal advisory: what the FBI and USSS said
The FBI and the U.S. Secret Service published a joint advisory on Tuesday documenting a sustained criminal campaign linked to what researchers call "FortiBleed." The agencies cited verification by SOCRadar that more than 86,644 devices across 194 countries were compromised. The advisory describes intrusions that create new administrative accounts on affected systems and, in some cases, delete or alter existing accounts so victims can be locked out while attackers maintain persistence and move laterally within environments. The agencies encouraged victims to report incidents but explicitly noted organizations were not obliged to provide information in response to the advisory.
Scope and targets: FortiGate firewalls and SSL VPN gateways
The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways. SOCRadar's verification figure — 86,644 compromised devices in 194 countries — is cited by the FBI and Secret Service as the basis for the advisory's urgency. The advisory links the threat to management access exposed on the internet and stresses the risk that attackers can alter account state on those devices to deny legitimate administrative access.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTechnique: credential stuffing, password spraying, hash extraction and GPU cracking
According to the advisory, criminals obtain credentials from earlier breaches and from infostealer logs and use them in credential stuffing and password spraying against vulnerable Fortinet devices. During intrusions, operators create new accounts and, in certain cases, delete existing accounts to lock defenders out. The actors also extract password hashes from compromised devices and crack those hashes offline using GPU-accelerated clusters. The advisory frames these steps as part of an attack chain that supports persistence and lateral movement within victim environments.
Links to ransomware: initial access brokers, INC/Lynx and Payload
The agencies said that initial access brokers furnished compromised network access to ransomware affiliates. The current evidence cited in the advisory points to affiliates working for the INC/Lynx and Payload ransomware groups making use of credentials tied to FortiBleed. SOCRadar reported in July that it had seen at least 12 confirmed ransomware attacks that stemmed from FortiBleed activity. The FBI and Secret Service also warned against paying ransoms and suggested that victim reports could help identify indicators of compromise.
What this means for technologists, affected enterprises, and incident responders
- Technologists and security teams: immediately restrict internet-facing management access, terminate active administrative and VPN sessions, reset passwords and enable phishing-resistant multi-factor authentication as urged by the agencies.
- Affected enterprises and procurement leaders: assess exposure of FortiGate firewalls and SSL VPN gateways in public-facing networks and prioritize remediation where external management access exists; treat password reuse and infostealer exposure as direct risk vectors.
- Incident responders and reporting teams: consider filing reports with the FBI or Secret Service to contribute indicators of compromise, while noting that the advisory states organizations are not required to provide information.
The FBI and Secret Service advisory compresses a series of practical concerns into a short checklist: lock down internet-facing management, end active sessions, rotate credentials and adopt phishing-resistant MFA. It also connects those defensive urgencies to an operational reality — attackers are not merely probing devices, they are creating and removing accounts and using offline cracking to convert stolen hashes into usable credentials. The agencies’ counsel to avoid paying ransoms closes the advisory with a blunt policy stance and an appeal for voluntary reporting that could sharpen indicators for future detection.
Read the original advisory and reporting at The Register: FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks




