86,644 devices across 194 countries have been reported compromised — a tally cited by the FBI and US Secret Service in a notice released on October 6 that warns the FortiBleed campaign remains active and can leave organizations locked out of their own systems.
Scope of the compromise: FortiGate firewalls and SSL VPN gateways
The FBI and Secret Service said the campaign targets Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. The advisory cites figures from SOCRadar showing the incident has already affected 86,644 devices in 194 countries. The campaign was first revealed in June after a security researcher discovered a trove of Fortinet usernames and plaintext passwords, the agencies noted.
How attackers are gaining and expanding access
According to the notice, attackers use automated tools to scan internet-exposed FortiGate SSL VPN portals, then rely on credential stuffing and password spraying based on prior Fortinet leak dumps and infostealer logs to gain initial access. Once attackers locate and exfiltrate additional credentials, they leverage a “GPU-accelerated cracking cluster” running Hashcat and Hashtopolis to decrypt passwords into plaintext.
- Cracked credentials are “enriched, sorted and validated,” with scripts that filter out honeypots, map organizations and prioritize high-value targets based on revenue and network structure.
- New administrative accounts are created on the firewall to maintain persistence.
- With verified credentials, attackers conduct Active Directory enumeration and password spraying to expand access and identify privileged accounts.
The advisory also names ransomware affiliates from INC, Lynx and Payload groups as among those using compromised credentials for initial access.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleFBI and Secret Service mitigation and incident-response steps
The notice lists specific steps organizations should take if they detect possible compromise. The agencies urged administrators to:
- Isolate compromised hosts by quarantining or taking them offline.
- Perform threat hunting to scope the intrusion.
- Report the compromise to the FBI or Secret Service.
- Use CISA’s Eviction Strategies Tool to evict the threat actor.
- Harden the network by locking down management access.
- Terminate admin/VPN sessions and reset credentials.
- Enable phishing‑resistant multi‑factor authentication (MFA).
- Review firewall and VPN users and other configurations for unauthorized changes.
- Review firewall, VPN, authentication, and domain controller logs for lateral movement.
- Ensure secure credential storage using the PBKDF2 algorithm.
The agencies cautioned that “affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets.”
What this means for technologists, procurement leaders, and affected enterprises
- Technologists and security teams must treat detected FortiGate credential exposure as an emergency: isolate hosts, hunt for lateral movement and verify firewall accounts and configurations against unauthorized changes.
- Procurement and operations leaders should prioritize management‑plane protections and deploy phishing‑resistant MFA where possible, while ensuring credential storage adheres to PBKDF2 guidance.
- Affected enterprises will need to consider eviction measures beyond simple password resets — the advisory directs organizations to the FBI/Secret Service and to CISA’s Eviction Strategies Tool for guided remediation.
Expert concern and a final observation
John Strand, owner of Black Hills Information Security, highlighted the campaign’s most troubling feature: the silent persistence it grants to attackers. “I’m not nearly as worried about an attacker who gets into an organization, locks everything down, and announces their presence,” he said. “I’m terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access.”
The FBI and Secret Service notice combines a detailed description of attacker tradecraft — from credential stuffing to GPU‑accelerated cracking and scripted target prioritization — with operational guidance that stresses both containment and eviction. For organizations running exposed FortiGate SSL VPN portals, the agencies make clear that detection and remediation must go beyond standard patching and password resets if they are to prevent lockouts and the long‑term persistence described by Strand.
https://www.infosecurity-magazine.com/news/fbi-secret-service-fortibleed/




