Skip to main content
Emerging ThreatsMalware & Ransomware

FBI Warns of Ongoing FortiBleed Threat Targeting Fortinet Devices

Rows of rack-mounted network devices with blinking lights in a brightly-lit data center.

86,644 working device credentials spanning 194 countries as of June 19, 2026 — a single tally that underscores why the Federal Bureau of Investigation and the U.S. Secret Service say the FortiBleed campaign "remains an active threat" to internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.

What the FBI and USSS reported

The FBI and U.S. Secret Service warned that the campaign exploits reused or leaked credentials and legacy SHA-256 password storage, allowing attackers to harvest and crack authentication data at scale. The agencies said initial findings show attackers continue to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials. They advised that, if compromise is detected, organizations should isolate affected devices, collect artifacts and logs, report the incident to the FBI and USSS, and apply relevant countermeasures.

How FortiBleed works: the five-stage campaign

According to the advisory, FortiBleed is organized as a five-stage operation. It begins with widespread reconnaissance to locate exposed portals, then uses credential stuffing and password spraying informed by prior leak dumps and infostealer logs to gain access. Once on a device, the adversary deploys a Go-based tool called FortigateSniffer to passively intercept authentication traffic across 24 protocols and harvest credentials and password hashes. Those hashes are sent to a GPU-accelerated cracking cluster that uses Hashmat and Hashtopolis for offline cracking. The attackers then perform lateral movement, Active Directory enumeration, Kerberos validation and SMB authentication, ultimately exfiltrating sensitive data from network shares while using stolen session cookies to preserve persistent, authenticated access.

Tools, tradecraft, and monetization

The agencies describe an industrialized pipeline: harvested credentials and hashes are cracked offline, enriched, sorted and validated; scripts filter out honeypots, map organizations and prioritize high-value targets by revenue and network structure; and new administrative accounts are created on appliances to maintain persistence. The adversary is suspected to be an initial access broker packaging stolen information for sale to downstream actors — a suspicion reinforced by operator overlaps tying FortiBleed-derived access to INC and Lynx ransomware operations.

Observed impacts on Fortinet appliances and user accounts

Attackers have been observed creating new administrative accounts on compromised Fortinet devices and, in some cases, deleting or changing passwords for original accounts — actions that can lock victims out of their hardware. The bulletin lists commonly identified compromised account names, including:

  • adminin
  • fortiAdmin
  • forticloud-sync
  • admin
  • fgtsecure
  • pakedge
  • forticloud-tech
  • districtadmin
  • system_config
  • gttadmin
  • roadmin
  • itadmin
  • Technical_support
  • adminsslvpn
  • IT_Manager
  • my_admin
  • support_fortinet
  • fgtsec
  • forti_support2

What CISA recommended for Fortinet customers

Following initial reporting by SOCRadar and Hudson Rock in June 2026, the U.S. Cybersecurity and Infrastructure Security Agency urged Fortinet customers to take specific actions: enable phishing-resistant authentication; terminate active SSL VPN and administrative sessions; reset Fortinet VPN and administrative passwords; use the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials; and review logs for signs of suspicious activity.

What this means for technologists, affected enterprises, and policymakers

Technologists and security teams: The advisory points them to concrete mitigations already urged by CISA — enable phishing-resistant authentication, terminate sessions, reset passwords, migrate administrator credential storage to PBKDF2, and review logs; isolate affected devices and collect artifacts if compromise is suspected.

Affected enterprises and procurement leaders: Organizations face the immediate risk of losing access to appliances if attackers delete or change original accounts; they should be prepared to isolate devices, follow collection and reporting procedures to federal authorities, and prioritize remediation for internet-facing FortiGate firewalls and SSL VPN gateways.

Policymakers and regulators: The advisory ties the campaign to an initial access brokering model and to downstream ransomware abuse, signaling a continuing policy concern about access economies and how stolen credentials are monetized and reused across criminal operations.

FortiBleed, as described in the bulletin, is not a single exploit but a chain: reconnaissance, credential-based access leveraging leaked data and legacy hash storage, large-scale passive harvesting with FortigateSniffer, GPU-accelerated cracking, and noisy lateral activity that ends in data theft or resale of access. The scale reported — more than 86,644 working credentials spanning 194 countries as of June 19, 2026 — and the observed links to ransomware actors frame this as an ongoing operational problem, not an isolated incident. Organizations operating internet-facing Fortinet appliances that have not yet followed the specific CISA and federal guidance should consider those steps immediate priorities; those already responding must also be alert for created administrative accounts and deleted originals that can lock them out of devices.

Original story: https://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.html