FortiBleed Attacks Continue As FBI Warns Of Firewall Takeovers

Federal agencies confirm ongoing credential harvesting and administrative lockouts across thousands of exposed Fortinet devices worldwide.

The FBI and US Secret Service warn that the FortiBleed campaign is actively locking organizations out of internet-facing Fortinet firewalls using stolen credentials.

Key takeaways
  • The FBI and US Secret Service published a joint advisory confirming ongoing attacks linked to the FortiBleed campaign in October 2026.
  • SOCRadar verified more than 86,644 compromised devices across 194 countries tied to these threat actor activities.
  • Attackers extract password hashes from compromised Fortinet appliances and crack them offline using GPU-accelerated clusters.
  • Federal agencies recommend restricting internet-facing management access, resetting passwords, and deploying phishing-resistant multi-factor authentication.
In short

The FortiBleed campaign involves threat actors using stolen credentials from infostealer logs and prior breaches to compromise internet-facing Fortinet firewalls and SSL VPN gateways. According to an FBI and USSS advisory, attackers create new accounts and delete original credentials to lock organizations out of their devices.

Why The FortiBleed Campaign Puts Corporate Networks At Immediate Risk

The FortiBleed campaign represents a critical escalation in how criminal syndicates target perimeter infrastructure, utilizing credential stuffing and offline hash-cracking to lock organizations out of their own Fortinet firewalls. According to a joint advisory published by the FBI and the US Secret Service in October 2026, threat actors are leveraging infostealer logs and prior breach datasets to access internet-facing FortiGate firewalls and SSL VPN gateways. Once inside, these operators create unauthorized administrative accounts and systematically delete or modify legacy credentials to maintain persistent access. This strategy effectively blinds internal security teams, preventing them from auditing the system or revoking compromised sessions during active lateral movement across enterprise environments.

The sheer scale of this campaign underscores a fundamental failure in perimeter hygiene. Intelligence verified by threat intelligence firm SOCRadar indicates that more than 86,644 devices spread across 194 countries exhibit indicators of compromise linked to these operations. When attackers extract password hashes from a breached appliance, they deploy GPU-accelerated computing clusters to crack them offline, bypassing standard rate limits and account lockout policies. This operational tempo transforms a routine credential stuffing exercise into a high-speed infrastructure takeover, often preceding direct ransomware deployment.

The Three-Tier Perimeter Defence Framework

Securing enterprise infrastructure against automated credential harvesting requires a structured triage model that separates baseline hygiene from advanced mitigations. Security teams must evaluate their posture using a tiered framework that addresses exposure, authentication integrity, and session lifecycle management. Neglecting any single tier leaves an opening for attackers to leverage harvested password hashes or brute-force legacy configurations.

  • Exposure Reduction: Immediately remove administrative management interfaces and SSL VPN portals from the public internet, restricting access strictly to validated internal networks or Zero Trust network access proxies.
  • Identity Hardening: Strip legacy username-password combinations from all administrative accounts and enforce phishing-resistant multi-factor authentication across every gateway interface.
  • Session Auditing: Terminate all active administrative and VPN sessions immediately upon discovering suspicious activity, followed by a comprehensive audit of user accounts for unauthorized creations.

Implementing these three operational layers halts the automated feedback loop that allows attackers to progress from initial perimeter breach to full domain dominance. Organizations that rely solely on default vendor configurations remain prime targets for GPU-accelerated offline cracking operations.

During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system.

What To Watch Next

Tracking the evolution of this threat campaign requires monitoring specific indicators and regulatory responses over the coming quarters. Security leadership should keep a close watch on three concrete signals to gauge organizational risk and defensive readiness.

  • Emergency CISA Directives: Watch for binding operational directives from federal cybersecurity agencies targeting vendor-specific management interfaces or mandating specific firmware baselines.
  • Infostealer Log Proliferation: Monitor dark web intelligence feeds for spikes in corporate credential dumps originating from employee endpoints and contractor machines.
  • Ransomware Dwell-Time Metrics: Track industry incident reports for shifts in the average time elapsed between initial FortiBleed intrusion events and subsequent extortion demands.

Frequently asked

What is the FortiBleed campaign?

The FortiBleed campaign is a cyber threat operation where bad actors use credentials from earlier breaches and infostealer logs to target internet-facing Fortinet firewalls and SSL VPN gateways, often locking administrators out of their own systems.

How many devices are affected by FortiBleed?

According to verification by SOCRadar cited in federal advisories, more than 86,644 compromised devices across 194 countries have been linked to the broader campaign dynamics.

How do attackers lock organizations out of Fortinet devices?

Attackers log into compromised gateways using harvested credentials, create unauthorized administrative accounts, and delete or change the passwords of original accounts to maintain persistent access and block internal IT teams.

What recommendations have the FBI and USSS provided?

The FBI and US Secret Service urge organizations to restrict internet-facing management access, terminate active administrative and VPN sessions, reset all passwords, and enforce phishing-resistant multi-factor authentication.

This article answers
  • fortibleed attacks
  • fbi fortinet advisory
  • fortibleed campaign fbi warning
  • fortinet firewall locked out by hackers
  • what is fortibleed security vulnerability
  • how to protect fortinet firewalls from credential stuffing
  • fbi and usss joint advisory fortibleed
  • socradar fortibleed compromised devices count
  • why are attackers locking out fortinet administrators
  • how do threat actors crack fortinet password hashes
Topics
A
Anamika
Senior Business & Policy Correspondent

Anamika reports on funding, market structure and technology regulation. Her work focuses on the commercial and compliance consequences of new technology — what it costs, who is liable, and which rules are about to change.

Startup fundingTech policyCybersecurityMarket analysis