HomeSecurityCISA warns about FortiBleed - 86,644 FortiGate devices compromised

CISA warns about FortiBleed – 86,644 FortiGate devices compromised

The U.S. Cybersecurity and Infrastructure Security Administration (CISA) has issued an urgent warning to organizations using Fortinet’s FortiGateafter uncovering a widespread cyberattack campaign that has already affected tens of thousands of systems worldwide. The operation, codenamed FortiBleed, is considered one of the largest coordinated attempts to breach perimeter security infrastructure in recent years.

FortiBleed FortiGate

According to the latest figures, at least 86,644 internet-accessible FortiGate devices have been exposed or compromised. Security analysts attribute the campaign to Russian-speaking threat actors, who appear to have developed fully automated methods to collect and exploit login credentials.

Default credentials at the center of attacks

SOCRadar 's analysis reveals a particularly worrying finding: Approximately 35% of the compromised accounts are general administrator accounts, while an additional 28.3% are built-in accounts within the Fortinet system itself.

See also: Fortinet FortiSandbox: Exploiting three critical vulnerabilities

This data shows that a large number of organizations are still using defaultcredentials or maintaining accounts with default names. Even more worrying is the fact that 36.7% of the accounts involve credentials created by the organizations themselves, which suggests the potential reuse of passwords that were leaked in previous security incidents.

How the FortiBleed campaign works

The attackers allegedly scoured the internet looking for Fortinet VPN portals and remote management interfaces, then used specially designed automation tools to test huge lists of known username and password combinations.

Their methodology is based on two sequential stages. First, they attempt to use leaked credentials collected from previous breaches. Once a device is accessed, the attackers monitor the network traffic passing through it, aiming to collect additional login details.

New credentials are checked, verified, and added to a constantly updated database of operational accounts. This is essentially a self-feeding mechanism that allows the attack to expand exponentially.

CISA warns about FortiBleed - 86,644 FortiGate devices compromised

The sectors most affected

The telecommunications, government, and education are the most affected by this campaign, with the most exposed devices located in India, the United States, Mexico, Colombia, and Thailand.

See also: Fortinet patches critical RCEs in FortiAuthenticator and FortiSandbox

Perimeter security devices, such as firewalls and VPN gateways, are particularly attractive targets for cybercriminals. Successfully breaching them can provide direct access to entire corporate networks, allowing attackers to move laterally, steal data, or even install ransomware.

Old password storage mechanisms create new problems

The UK's National Cyber ​​Security Centre notes that the campaign utilizes brute force techniques, dictionary attacks and credential stuffing.

Of particular interest is the way passwords are stored in older versions of FortiOS. Although Fortinet has adopted the stronger PBKDF2 in the most recent versions of its operating system, many organizations continue to use older SHA-256 hashes.

In practice, even after the software upgrade, old passwords are not automatically converted to the new security standard. The transition only occurs when administrators log back into the system, which does not seem to have happened in many cases.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Fortinet fixes zero-day vulnerability in FortiClient EMS

CISA warns about FortiBleed - 86,644 FortiGate devices compromised

CISA recommendations and the lesson for the market

CISA urges organizations to terminate all active VPN and management sessions, immediately reset all passwords , and implement strong authentication policies.

Additionally, it is recommended to enable multi-factor authentication phishing-resistant check log files for suspicious activity, and limit the attack surface through stricter access policies.

The FortiBleed case highlights once again that the largest breaches are not always due to unknown zero-day vulnerabilities. Too often, password reuse, careless account management, and delays in implementing basic security measures are enough to open the door to a global cyberattack.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS