Back to Articles
high

HIGH: Fortinet FortiBleed Credential Campaign Still Active, FBI Warns

The FBI and U.S. Secret Service warn that the FortiBleed operation is still active after amassing 86,644 working Fortinet FortiGate and SSL VPN credentials across 194 countries. The Russian-speaking access broker is cracking legacy SHA-256 hashes, planting rogue admin accounts, and selling access to INC and Lynx ransomware operators.

By Danny Mercer, CISSP — Lead Security Analyst • Oct 7, 2026
Is your business exposed? Our McKinney-based security team can assess your risk for free.
Share:

If you were hoping FortiBleed had quietly burned itself out over the summer, the FBI would like a word. On October 7, 2026, the Bureau and the U.S. Secret Service put out a joint warning that the credential harvesting operation aimed at Fortinet FortiGate firewalls and SSL VPN gateways is still running. The people behind it are still logging into devices with stolen passwords, still cracking hashes at scale, and still selling that access to ransomware crews. Four months after it was first disclosed, this is not a historical incident. It is an open case.

The headline number has not changed, and it was bad enough the first time. The operation has built a verified database of 86,644 working device credentials across 194 countries, counted as of June 19, 2026. Researchers at SOCRadar and Arctic Wolf independently spotted the campaign in June, it was formally disclosed on June 16, and CISA followed with an emergency advisory on June 18. By the Cloud Security Alliance's count, that pile of logins covers roughly half of all publicly reachable FortiGate devices in the world. Let that sink in for a second. Half.

No zero-day required

What makes FortiBleed so irritating from a defender's point of view is how little cleverness it needs. There is no single CVE at the center of it. The campaign runs on reused and leaked credentials and on a gap in how older FortiOS builds stored passwords. Fortinet moved administrator password storage from salted SHA-256 to the much stronger PBKDF2 algorithm in late 2025, but the upgrade only rewrote a hash when that account's owner actually logged in after the firmware update. Any admin account nobody touched kept its legacy SHA-256 hash, and backward compatibility left older hashes sitting in configuration fields that end up in backups. If your FortiGate has a service account that someone created in 2021 and never logged into again, there is a decent chance its password is still protected by the weaker scheme.

The FBI advisory lays out a five-stage playbook. It starts with plain reconnaissance of exposed management portals and VPN login pages. Next comes credential stuffing and password spraying fed by older breach dumps and infostealer logs. Once inside, the operators deploy a Go-based tool the FBI calls FortigateSniffer, which passively intercepts traffic across 24 protocols and pulls out credentials and password hashes moving through the box. Those hashes go to GPU-accelerated cracking rigs running Hashmat and Hashtopolis. The final stage is the one that turns a firewall problem into a company problem, with lateral movement into the internal network, Active Directory enumeration, data exfiltration, and theft of session cookies so access survives a password change.

The composition of the stolen credentials tells you everything about why this worked. Generic admin accounts make up 35 percent of the haul, and built-in Fortinet system accounts account for another 28.3 percent. Put another way, close to two thirds of the compromised logins belong to accounts that were either factory defaults or names like "admin" that nobody bothered to change. The remaining 36.7 percent are organization-specific accounts, which mostly says that password reuse is alive and well.

It is also worth remembering that FortiBleed did not happen in a vacuum. Earlier this year attackers were abusing CVE-2026-24858, a critical FortiCloud SSO authentication bypass rated CVSS 9.4, to create rogue local administrator accounts on otherwise fully patched devices. Some of the access that feeds this ecosystem came from that route, which is why turning off FortiCloud SSO on devices that have not been patched remains part of the cleanup advice.

Who is behind it and who is getting hit

Researchers describe the operators as Russian-speaking, and the FBI's read is that this looks like an initial access broker business. The group harvests and validates access, then sells it downstream. The Bureau specifically named the INC and Lynx ransomware operations among the buyers. That matters because it changes the threat model. The broker may only ever touch your firewall. The people who show up two weeks later with an encryptor are a different crew, and they will arrive with a valid VPN session and a map of your network already in hand.

Telecommunications providers sit at the top of the victim list, followed by government, where 111 government domains have been tied to compromised devices. Education, healthcare, finance, and energy also feature prominently. India and the United States together account for nearly a third of the identified compromises. In other words, this is not a targeted campaign against one sector. It is a dragnet, and the only qualification for being caught in it is an internet-facing FortiGate with a weak or recycled password.

The persistence tradecraft is where the FBI warning gets most practical. Operators are creating new administrator accounts with names designed to blend in, including adminin, fortiAdmin, forticloud-sync, fgtsecure, roadmin, itadmin, and Technical_support. If you have ever skimmed a list of local accounts and nodded past something that sounded vaguely official, you can see the logic. The Bureau also flagged a nasty side effect, warning that "some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts." Nothing says Monday morning like discovering the only person who can log into your perimeter firewall is a ransomware affiliate.

What to do right now

Start by assuming compromise if you run an internet-facing FortiGate that was online during the spring and summer and has not had a full credential reset since. The FBI recommends terminating every active SSL VPN and administrative session, because killing sessions is the only way to evict anyone riding on a stolen cookie. Then reset every VPN and administrative password, and make each one unique to the device and genuinely long. Reusing the same strong password across forty firewalls simply means one crack gets the attacker forty firewalls.

Next, get your password storage onto PBKDF2. According to the Cloud Security Alliance research note, the migration thresholds are FortiOS 7.2.11, 7.4.8, and 7.6.1. Upgrading alone is not enough, since the stronger hash only gets written when an account logs in after the upgrade. The cleanest approach is to rotate every local account's password after you upgrade, which forces the new format, and to delete any account nobody can explain.

While you are in there, audit the local admin list against the account names the FBI published, and treat anything you did not create as an incident rather than a curiosity. Disable or rename default accounts. Pull administrative interfaces off the public internet entirely and put them behind a management VPN or jump host. Enforce phishing-resistant MFA, meaning FIDO2 keys or certificate-based authentication, on both admin access and SSL VPN. SMS codes are better than nothing, but not by enough to matter against a group that steals session cookies for a living. If you are not current on the FortiCloud SSO fixes, disable FortiCloud SSO until you are.

On the detection side, review FortiGate event logs for administrator logins from unfamiliar addresses, configuration changes nobody approved, new admin or VPN accounts, and configuration backup downloads. Look for unexpected packet capture or sniffer activity on the device itself. Then follow the trail inward. Any VPN account that touched the network during the exposure window deserves a look in your Active Directory logs for enumeration, new privileged group memberships, and unusual authentication to domain controllers. If you find something, the FBI's guidance is to isolate the affected device and collect artifacts before wiping anything, because the firewall is evidence now.

The uncomfortable lesson here is that a perimeter device is only as strong as its least loved admin account. Fortinet shipped a better hashing scheme, but the fix depended on humans logging in, and the attackers bet correctly that many of them never would. FortiBleed is not a story about exotic exploitation. It is a story about defaults, stale accounts, and password reuse, the same three things we have been nagging about for twenty years, finally scaled up to an industrial operation.

The MSP angle

Every MSP with Fortinet in its client base should be running a FortiBleed sweep this week, covering session resets, credential rotation, PBKDF2 verification, and an admin account audit, and offering it as a fixed-price perimeter hygiene engagement to prospects who are not yet clients. It is also a natural opening to sell managed MFA rollouts and dark web credential monitoring, since the clients whose passwords showed up in infostealer logs are exactly the ones who got caught in this net.

References

Concerned about this threat?

Our security team can assess your exposure and recommend immediate actions.

Get a Free Assessment →