FBI and Secret Service: FortiBleed Has Amassed 86,644 Fortinet Credentials Across 194 Countries and Remains Active — Lockouts and Ransomware Deployments Follow

FBI and Secret Service: FortiBleed Has Amassed 86,644 Fortinet Credentials Across 194 Countries and Remains Active — Lockouts and Ransomware Deployments Follow

FBI and Secret Service: FortiBleed Has Amassed 86,644 Fortinet Credentials Across 194 Countries and Remains Active — Lockouts and Ransomware Deployments Follow

The FBI and the U.S. Secret Service warned on October 6 that FortiBleed — the credential-harvesting campaign first documented by SOCRadar and Hudson Rock in June — remains an active threat to internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, with more than 86,644 compromised devices across 194 countries verified by SOCRadar. The joint advisory (JCSA-20261006-01) is blunt about why this cannot be patched away: the campaign "exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale."

The attack chain runs five stages. It starts with automated scanning for exposed FortiGate SSL VPN portals, then credential stuffing and password spraying using material from prior leak dumps and infostealer logs. Valid access brings FortigateSniffer, a Go-based tool that passively intercepts authentication traffic across 24 protocols, harvesting credentials and password hashes. The hashes go to a GPU-accelerated cracking cluster running Hashcat and Hashtopolis, after which the operators enrich, sort and validate their haul — scripts filter honeypots, map organizations, and prioritize high-value targets by revenue and network structure — and create new administrative accounts on the firewall to keep the foothold. From there: Active Directory enumeration, Kerberos validation, SMB authentication, further password spraying, exfiltration from network shares, and stolen session cookies for persistent authenticated access. Several of the campaign's C2 servers themselves ran on compromised routers; the advisory names infrastructure including a C2 at 45.154.12[.]132, proxy nodes at 154.202.59[.]169 and 103.27.186[.]156, and a beacon relay at 45.155.250[.]158.

Two consequences stand out. First, lockouts: because the actors delete or change the passwords of original accounts (MITRE ATT&CK T1531), some victims are locked out of their own firewalls mid-incident — remediation "beyond standard patching and password resets," as the advisory puts it. Second, ransomware: the operators behave as an initial access broker, with overlaps tying FortiBleed to INC and Lynx ransomware operations; SOCRadar has confirmed at least 12 ransomware deployments stemming from this access, encrypting hundreds of endpoints, and initial-access brokers using the FortiBleed chain have also supplied access to Payload ransomware affiliates. SOCRadar CISO Ensar Seker's framing matches the agencies' tone: FortiBleed "should be treated as an active access operation, not as a one-time credential leak."

This is the second Fortinet story on this site in a week — days earlier we covered the actively exploited FortiMail zero-day CVE-2026-104286 — but the two share only the vendor. That one was a flaw to patch; this one is a credential economy to starve.

What Should You Do?

  1. Lock down management access now: the advisory ranks the options — restrict external management via trusted hosts (good), a local-in policy (better), or removing internet administration altogether (best).
  2. Terminate every active administrative and SSL VPN session and reset all Fortinet VPN and administrative passwords, enforcing strong, unique values — assume the current ones live in an infostealer dump somewhere.
  3. Require phishing-resistant MFA on all remote access and administrative accounts, enforced at every external gateway and administrative interface.
  4. Modernize credential storage and hunt persistence: enforce PBKDF2 for administrator credentials — legacy SHA-256 is what the GPU cluster eats — and audit for the advisory's commonly seen actor-created account names (adminin, forticloud-sync, fgtsecure and siblings).

The WAF Angle

There is no CVE in this campaign, so there is no signature to deploy — but the edge is still the battleground. FortiBleed's front door is your SSL VPN login page, and the attacks are credential stuffing and password spraying: exactly the traffic patterns WAF-class heuristics exist for — per-source velocity limits, failed-authentication thresholds, bot detection and impossible-travel flags on the VPN portal. Behind the edge, the deeper fixes are identity hygiene: phishing-resistant MFA makes stolen passwords inert, and retiring legacy SHA-256 storage removes the cracking economy's raw material. Treat any lockout of your own firewall administrators as a campaign indicator rather than an operational accident — account deletion is the tell the FBI and USSS wrote an entire advisory section about.

Sources