The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) have issued a warning regarding the persistent FortiBleed credential harvesting campaign. This campaign continues to target internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways.
The agencies indicate that attackers are actively scanning internet-exposed Fortinet firewalls using previously obtained compromised credentials. This activity can lead to legitimate administrators being locked out of their systems.
The FortiBleed campaign exploits reused or leaked credentials and legacy SHA-256 password storage. This method allows threat actors to harvest and crack authentication data on a large scale. Hackers gain access to exposed endpoints using previously leaked credentials or logins obtained from infostealer logs, credential stuffing, and password spraying attacks.
Once access is gained, attackers extract additional authentication data from compromised devices. They then use a distributed GPU cluster running Hashcat and Hashtopolis to crack stolen password hashes offline.
FortiBleed was first documented by SOCRadar in Hudson Rock in June 2026. The Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026.
This data revealed a large-scale credential-harvesting operation, although the exact method used to obtain the configuration data was initially unclear.
The FBI has observed the FortiBleed attack chain serving as an initial entry point for ransomware affiliates. Ransomware groups benefiting from this include INC/Lynx ransomware and Payload ransomware. In July, SOCRadar linked FortiBleed to the INC and Lynx groups.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) previously urged Fortinet customers with FortiGate appliances to enable phishing-resistant authentication. CISA also recommended terminating active SSL VPN and administrative sessions, and resetting Fortinet passwords.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The FBI issued a warning about ongoing FortiBleed attacks that target Fortinet FortiGate firewalls and SSL VPN gateways, leading to legitimate administrators being locked out. Attackers use leaked credentials to gain access, extract authentication data, and crack stolen password hashes offline, with some incidents linked to ransomware groups like INC/Lynx and Payload ransomware.
The FBI and USSS issued a warning that the FortiBleed campaign continues to target Fortinet FortiGate firewalls and SSL VPN gateways, exploiting reused credentials and legacy password storage. This ongoing threat has already amassed over 86,644 device credentials globally, enabling attackers to harvest and crack authentication data at scale.