HomeSecurityFBI warns: FortiBleed Threat remains active

FBI warns: FortiBleed threat remains active

The U.S. Federal Bureau of Investigation (FBI) and the U.S. Secret Service (USSS) warned Tuesday that the FortiBleed remains an active threat targeting Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways exposed to the internet.

See also: FortiBleed Foreign Office: UK Credentials on the Dark Web

Article Image: FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

“The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, allowing malicious actors to harvest and brute force authentication data at scale,” the agencies said. “Initial findings indicate that attackers are continuing to scan Fortinet’s exposed firewalls using previously acquired compromised credentials.”

FortiBleed was first detected by SOCRadar on Hudson Rock in June 2026, with the activity targeting thousands of Fortinet firewalls as part of a global campaign. In total, the Russian-speaking firm is estimated to have amassed more than 86,644 operational device credentials across 194 countries as of June 19, 2026.

The campaign subsequently prompted the U.S. Cybersecurity and Infrastructure Security Administration (CISA) to urge Fortinet customers with FortiGate devices to enable phishing-resistant authentication, terminate active SSL VPN and management sessions, reset VPN and Fortinet administrator passwords, use the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials, and review logs for signs of suspicious activity.

FortiBleed is a five-stage campaign that conducts extensive reconnaissance to identify exposed gateways, gains access to these devices using credential stuffing and password spraying based on data obtained from previous leaks and infostealer files, and then deploys a Go-based tool called FortigateSniffer to passively intercept authentication traffic across 24 protocols and collect credentials and password hashes.

The password hashes are then routed to a GPU-accelerated cracking cluster that uses Hashmat and Hashtopolis for offline cracking, after which they are used to facilitate lateral movement, Active Directory enumeration, Kerberos validation, and SMB authentication. In the final stage, sensitive data from shared networks is extracted while stolen session cookies are used to maintain persistent, authenticated access.

See also: Fortinet: Patches for critical vulnerabilities in FortiMonitorOnSight & Chrome Extension

FBI warns: FortiBleed threat remains active

“The compromised credentials were enriched, classified, and validated, with scripts to filter honeypots, map organizations, and prioritize high-value targets based on revenue and network structure,” the services said. “New administrator accounts were created on the firewall to maintain persistence.”

With validated credentials in hand, attackers have been found to move deeper into victims' environments, conducting enumeration and performing password spraying to expand access and identify privileged accounts.

Additionally, initial access is used to add new accounts to the system as a way to maintain persistence on the device. Some of the commonly recognized names of compromised accounts are listed below.

The adversary is suspected of being an initial access broker that packages stolen information and sells it to lower-tier malicious actors. This is evidenced by the fact that operator overlaps link FortiBleed to ransomware operations INC and Lynx, potentially indicating that access is being abused to develop ransomware.

“Based on initial responses, some victims may be locked out of their Fortinet devices if the malicious actor either deletes or changes the password for the original accounts on the system,” the FBI and USSS warned.

“During the initial intrusion, malicious actors create new accounts that did not previously exist on the device. In some cases, malicious actors delete existing accounts to prevent organizations from accessing affected devices and maintain persistence on the system while attempting lateral movement within the environment.“

See also: Fortinet's new FortiGate platform combines firewall and SASE technologies

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CVE-2026-26035 FortiWeb Fortinet authentication vulnerability

If a potential breach is identified, organizations are advised to isolate affected devices, collect necessary files and logs, report the incident to the FBI and USSS, and implement relevant countermeasures.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS