FBI and Secret Service warn FortiBleed is still hijacking Fortinet firewalls
A joint FBI and Secret Service advisory says the FortiBleed campaign, which harvested working credentials for more than 86,000 FortiGate devices, remains active and feeds ransomware gangs.
At a glance
- SOCRadar counted 86,644 working Fortinet device credentials across 194 countries as of June 19, 2026.
- Attackers create new admin accounts and may delete or change original ones, locking out administrators.
- Stolen access has been linked to INC/Lynx and Payload ransomware affiliates.
- Agencies urge password resets, session termination, account review and restricting external management.
The FBI and the U.S. Secret Service have warned that FortiBleed, a large-scale credential harvesting campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, is still active. According to The Hacker News, the joint advisory was released on October 7, 2026, months after security firm SOCRadar first documented the operation in June. SOCRadar said it had verified 86,644 working device credentials across 194 countries as of June 19, making the campaign one of the largest known efforts to compromise edge security devices.
What happened
The agencies said that "attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials," The Record reported. The outlet said the operation involves more than 20 affiliates in defined roles across several countries, and that at least 12 organizations have been breached and encrypted with ransomware. Scanning activity has reached more than 150 countries.
The Hacker News described the operation as a suspected Russian-speaking, five-stage campaign. Initial access brokers sort and validate stolen credentials by factors such as victim revenue and network structure, then sell the access. Operator overlaps link FortiBleed to the INC and Lynx ransomware operations, while Help Net Security also cited links to Payload ransomware affiliates.
Technical details
According to the reporting, the attackers rely on credential stuffing and password spraying using credentials from earlier breach dumps rather than a new software vulnerability; no CVE is cited in the advisory coverage. The Hacker News said the operators use a Go-based tool dubbed FortigateSniffer to intercept authentication across 24 protocols, and GPU-accelerated cracking clusters with Hashcat and Hashtopolis to break password hashes, taking advantage of legacy SHA-256 password storage. After gaining access, they enumerate Active Directory accounts to find privileged users and move laterally.
For persistence, the actors create new administrative accounts that did not previously exist on the device. Help Net Security quoted the advisory as warning that some victims "may get locked out of their Fortinet devices" if the attacker deletes or changes the password of the original accounts. Account names observed on victim devices include fortiAdmin, forticloud-sync, fgtsecure, roadmin, adminsslvpn, support_fortinet and forti_support2. The advisory also lists attacker IP addresses.
Who is affected
Any organization running an internet-exposed FortiGate firewall or SSL VPN portal with reused, weak or previously leaked credentials is at risk. The agencies cautioned that recovery may require steps beyond standard patching and password resets, since attackers may already hold valid accounts.
What to do
The FBI and Secret Service recommend reviewing every Fortinet account for legitimacy, removing unknown administrators, resetting VPN and administrative passwords, and terminating active SSL VPN and admin sessions. Organizations should enable phishing-resistant multi-factor authentication, use the PBKDF2 algorithm for credential storage, restrict or eliminate external device management, and review logs for suspicious logins. Compromised devices should be isolated, and incidents can be reported to the FBI or Secret Service.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



