Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published • loading... • Updated

FBI: Ongoing FortiBleed Attacks Lock Out FortiGate VPN Admins

The agencies say attackers use stolen credentials to create new accounts, disable existing ones and route access to ransomware affiliates.

  • On Tuesday, the FBI and Secret Service issued an alert warning that the ongoing FortiBleed campaign targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, with attackers locking organizations out of their own devices.
  • Hackers exploit previously leaked credentials through credential stuffing and password spraying, then extract password hashes to crack offline using GPU-accelerated Hashcat and Hashtopolis clusters; this campaign initially exposed credentials for 73,932 firewall URLs earlier this year.
  • SOCRadar verified more than 86,644 compromised devices across 194 countries, confirming the attack chain serves as an initial entry point for ransomware affiliates including INC, Lynx, and Payload.
  • "Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," the advisory states.
  • Ensar Seker, chief information security officer at SOCRadar, identified more than 400,000 targeted firewalls in later investigations, noting the figures "show the campaign is broader and more serious than we understood at the beginning.
Insights by Ground AI

14 Articles

The RegisterThe Register
Reposted by
IT Security News - cybersecurity, infosecurity newsIT Security News - cybersecurity, infosecurity news
Center

FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks

Tens of thousands more victims and more ransomware groups getting in on the act

·London, United Kingdom
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 83% of the sources are Center
83% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

CyberScoop broke the news in Washington, United States on Tuesday, October 6, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal