73,932 firewall URLs across 194 countries — that is the core of a June credential leak now driving active, disruptive intrusions against Fortinet FortiGate firewalls and SSL VPN gateways.
What the FortiBleed leak revealed
FortiBleed began as a massive credential disclosure discovered in June when attackers inadvertently exposed a server containing usernames and plaintext passwords tied to tens of thousands of FortiGate endpoints. The leak “revealed a large-scale credential-harvesting operation,” the record shows, though the original method used to collect device configurations was unclear at the time. Investigators later observed the data being reused in automated campaigns that probe and compromise externally exposed Fortinet appliances.
How attackers turn leaked data into administrator lockouts
The FBI reports attackers reach exposed endpoints by reusing leaked credentials, mining infostealer logs, and conducting credential-stuffing and password-spraying attacks. Once they gain access, intruders extract additional authentication data from the compromised devices and export password hashes for offline cracking. To crack those hashes they run Hashcat and Hashtopolis on a distributed GPU cluster.
According to the FBI, intruders sometimes create new administrator accounts, then use those privileges to delete existing admin accounts or change passwords — effectively locking legitimate administrators out of their devices. After the lockout, attackers work to establish persistence and attempt lateral movement within victim environments.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadTools and automation exposed by an operator error
Operational details became public after the threat actor accidentally exposed their backend server. The exposed directory showed coordinated tooling and datasets: automated scripts that scanned exposed FortiGate SSL VPN portals; a distributed GPU password-cracking setup; and validation scripts that filtered out honeypots, identified high-value organizations, and prioritized targets by revenue and network structure. The exposure also included working VPN configurations and target lists, suggesting the operator was packaging compromised access for sale.
Ties to ransomware affiliates: INC/Lynx and Payload
The FBI cautioned that “the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.” Security researchers linked the leak to known ransomware operations: in July SOCRadar said it connected FortiBleed to INC and Lynx after gaining access to both groups’ negotiation panels on a server used in the campaign. The same tracking now credits FortiBleed with compromising 86,644 devices, and the FBI named INC/Lynx ransomware and Payload ransomware among groups that have benefited from the access.
FBI remediation guidance for Fortinet administrators and network teams
The FBI warned that merely patching appliances and resetting Fortinet passwords may not be sufficient. Recommended actions include restricting external access to FortiGate and SSL VPN interfaces, terminating all active VPN sessions, enforcing multi-factor authentication (MFA), and reviewing logs for unauthorized changes and suspicious activity. The agency also urged enforcing PBKDF2 for administrator password storage — noting it is “much stronger than legacy SHA-256 hashes that attackers can practically crack offline.”
What this means for technologists, affected enterprises, and adversaries
- Technologists and security teams: Expect attackers to leverage large credential datasets, automated scanning, and offline cracking operations; prioritize removing external exposure, enforcing MFA, and migrating admin password hashing to PBKDF2 as the FBI recommends.
- Affected enterprises and procurement leaders: Compromised VPN credentials and working VPN configurations may be sold or packaged — organizations should assume any externally reachable FortiGate portal could be probed and prioritize session termination and targeted log reviews.
- Adversaries and ransomware affiliates: The chain demonstrates how initial access from credential reuse can be monetized by ransomware operations; the FBI’s linkage to INC/Lynx and Payload shows access can feed affiliate ecosystems.
The FortiBleed episode illustrates a simple, unforgiving truth: large-scale credential leaks can power automated, GPU-accelerated campaigns that not only obtain access but also erase legitimate control. The FBI’s guidance — restrict exposure, force session resets, require MFA, and move admin hashing to PBKDF2 — is specific and operational; whether organizations implement those steps quickly will determine how many more devices become footholds for ransomware affiliates.




