← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

FBI Warns FortiBleed Campaign Continues to Target Fortinet Devices, Amassing Credentials

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • FortiBleed campaign actively targets Fortinet FortiGate firewalls and SSL VPN gateways.
  • Attackers exploit reused credentials and legacy SHA-256 password storage.
  • Over 86,644 device credentials have been amassed across 194 countries.
  • Compromised credentials are used for initial access, leading to admin lockouts.
  • Some attacks are linked to ransomware groups like INC/Lynx and Payload ransomware.

Ongoing Threat to Fortinet Devices

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) have issued a warning regarding the persistent FortiBleed credential harvesting campaign. This campaign continues to target internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways.

The agencies indicate that attackers are actively scanning internet-exposed Fortinet firewalls using previously obtained compromised credentials. This activity can lead to legitimate administrators being locked out of their systems.

Credential Exploitation and Harvesting

The FortiBleed campaign exploits reused or leaked credentials and legacy SHA-256 password storage. This method allows threat actors to harvest and crack authentication data on a large scale. Hackers gain access to exposed endpoints using previously leaked credentials or logins obtained from infostealer logs, credential stuffing, and password spraying attacks.

Once access is gained, attackers extract additional authentication data from compromised devices. They then use a distributed GPU cluster running Hashcat and Hashtopolis to crack stolen password hashes offline.

Scale of Compromise

FortiBleed was first documented by SOCRadar in Hudson Rock in June 2026. The Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026.

This data revealed a large-scale credential-harvesting operation, although the exact method used to obtain the configuration data was initially unclear.

Links to Ransomware

The FBI has observed the FortiBleed attack chain serving as an initial entry point for ransomware affiliates. Ransomware groups benefiting from this include INC/Lynx ransomware and Payload ransomware. In July, SOCRadar linked FortiBleed to the INC and Lynx groups.

Recommendations for Fortinet Users

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) previously urged Fortinet customers with FortiGate appliances to enable phishing-resistant authentication. CISA also recommended terminating active SSL VPN and administrative sessions, and resetting Fortinet passwords.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~5 min · 3 stories · Oct 07

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The FBI issued a warning about ongoing FortiBleed attacks that target Fortinet FortiGate firewalls and SSL VPN gateways, leading to legitimate administrators being locked out. Attackers use leaked credentials to gain access, extract authentication data, and crack stolen password hashes offline, with some incidents linked to ransomware groups like INC/Lynx and Payload ransomware.

The FBI and USSS issued a warning that the FortiBleed campaign continues to target Fortinet FortiGate firewalls and SSL VPN gateways, exploiting reused credentials and legacy password storage. This ongoing threat has already amassed over 86,644 device credentials globally, enabling attackers to harvest and crack authentication data at scale.