FBI: Ongoing FortiBleed Attacks Lock Out FortiGate VPN Admins
The agencies say attackers use stolen credentials to create new accounts, disable existing ones and route access to ransomware affiliates.
- On Tuesday, the FBI and Secret Service issued an alert warning that the ongoing FortiBleed campaign targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, with attackers locking organizations out of their own devices.
- Hackers exploit previously leaked credentials through credential stuffing and password spraying, then extract password hashes to crack offline using GPU-accelerated Hashcat and Hashtopolis clusters; this campaign initially exposed credentials for 73,932 firewall URLs earlier this year.
- SOCRadar verified more than 86,644 compromised devices across 194 countries, confirming the attack chain serves as an initial entry point for ransomware affiliates including INC, Lynx, and Payload.
- "Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," the advisory states.
- Ensar Seker, chief information security officer at SOCRadar, identified more than 400,000 targeted firewalls in later investigations, noting the figures "show the campaign is broader and more serious than we understood at the beginning.
14 Articles
14 Articles
FBI Sounds Alarm as FortiBleed Campaign Persists, Locking Firms Out of Their Own Firewalls
Tens of thousands of organizations remain exposed. Their Fortinet firewalls and VPN gateways sit on the public internet, quietly hemorrhaging credentials. On October 7, the FBI and U.S. Secret Service issued a fresh warning. The operation known as FortiBleed shows no signs of slowing. More than 86,644 devices across 194 countries have already been compromised. That’s according to data verified by threat intelligence firm SOCRadar and cited direc…
FBI warns FortiBleed activity is still ongoing
The FBI says exposed Fortinet FortiGate firewalls and SSL VPN gateways continue to be targeted in the FortiBleed campaign. Operators use leaked or stolen credentials, extract additional auth data, crack password hashes offline with distributed GPU...
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
Tens of thousands more victims and more ransomware groups getting in on the act
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
The FBI and Secret Service warn that the FortiBleed campaign has targeted over 400,000 Fortinet devices, locking users out and enabling ransomware attacks.
Coverage Details
Bias Distribution
- 83% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium












