Skip to main content
Emerging ThreatsMalware & Ransomware

FBI Warns of Ongoing FortiBleed Threat

Technicians in a network operations room monitor Fortinet firewalls and VPN gateways with concern.

“Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the FBI and Secret Service warned in an alert published Tuesday.

FBI and Secret Service: FortiBleed remains active and dangerous

The joint advisory from the FBI and the Secret Service describes FortiBleed as an ongoing campaign that targets Fortinet firewalls and VPN gateways to harvest credentials and take over administrative access. The two agencies emphasize that the operational impact goes beyond simple credential theft: attackers have used stolen access to disable accounts or change passwords, effectively locking legitimate owners out of their systems. The advisory also links this access to follow-on criminal activity, noting that the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.

Scope and scale: SOCRadar’s early figures and later findings

When FortiBleed was first uncovered earlier this year, SOCRadar reported verification of more than 86,644 compromised devices across 194 countries. SOCRadar's chief information security officer, Ensar Seker, told CyberScoop that subsequent investigation expanded the estimate substantially: “in our later investigation, we identified more than 400,000 or 450,000 firewalls targeted by the wider operation.” Seker cautioned that different aspects of the operation make precise comparisons difficult, but he said the evolving numbers "show the campaign is broader and more serious than we understood at the beginning.”

Tactics observed: account takeover and handoffs to ransomware affiliates

The government alert highlights two operational features that raise the threat level. First, attackers use compromised Fortinet devices not only to view traffic or steal data but to create new administrative accounts and alter credentials, an activity that can lock the legitimate owners out and make simple patching or password resets inadequate. Second, the alert states that initial access brokers are leveraging FortiBleed to sell or hand off access to ransomware affiliates — listing INC/Lynx and Payload as observed beneficiaries. The combination of persistent administrative control and explicit ties to ransomware operators elevates FortiBleed from an incident of isolated device compromise to a strategic access point for larger criminal campaigns.

Practical remediation steps recommended by the agencies

To blunt the campaign’s impact, the FBI and Secret Service issued several concrete recommendations for Fortinet customers. The advisory urges organizations to restrict external management access or remove internet-facing administration entirely, reset credentials, and implement multifactor authentication. Operators are also advised to review firewall and VPN user lists for unauthorized changes, check logs for signs of lateral movement, and enable secure credential storage. Finally, the agencies are requesting that victims and observers share indicators of compromise, including IP addresses and any attacker-supplied usernames, to help track and disrupt the campaign.

What this means for security teams, procurement leaders, and the general public

  • Security teams: Expect remediation to require more than an emergency patch or a password reset. The advisory underscores the need to inventory administrative accounts, look for new or altered accounts, and hunt for lateral movement after initial access.
  • Procurement and operations leaders: Devices that allow internet-facing administration should be re-evaluated; the agencies explicitly recommend restricting or removing external management capabilities to reduce exposure.
  • The general public and non-technical leaders: The campaign’s connection to ransomware affiliates means disruptions may cascade beyond isolated firewall outages; compromised devices have been used to enable access that later resulted in ransomware activity.

FortiBleed’s persistence, the large number of targeted devices reported by SOCRadar, and the explicit warning from the FBI and Secret Service together present a clear, immediate operational threat. Organizations that rely on Fortinet appliances should assume that simple remediation—patching and resetting a password—may not be sufficient, and they should follow the agencies’ checklist while sharing indicators of compromise to aid wider detection and disruption efforts. The agencies’ appeal for IP addresses and usernames signals that containment will depend on coordinated reporting as much as on individual fixes.

Source: CyberScoop — Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks