Threats · 2h ago
The FBI and U.S. Secret Service say FortiBleed is still targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, and that the campaign has already collected more than 86,644 working device credentials across 194 countries. The agencies say attackers are still scanning exposed devices with previously stolen logins.
The campaign starts with reused or leaked passwords, then uses a FortiGate sniffer to capture authentication traffic and harvest password hashes from the device itself. Those hashes are cracked offline in bulk, so the operation keeps finding new working logins without staying online for long, and stolen session cookies can keep access alive after a reset.
For any network that uses FortiGate as the front door, the exposure is not just the password that was reused first; it is the firewall account, the VPN session, and whatever the gateway can reach once those credentials are cracked and reused. A reset-only response can miss already-harvested sessions and accounts that were recovered offline.
6 sources covering this story
FBI warns that FortiBleed credential-harvesting attacks are locking out firewall users
An initial access broker is working with various ransomware groups in a global campaign.
Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, U.S.
The Record from Recorded Future
FBI, Secret Service add to warnings of FortiBleed credential stealing campaign
Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S.
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
FBI and USSS warn FortiBleed remains active, using stolen credentials and traffic sniffing to harvest Fortinet authentication data.
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
Tens of thousands more victims and more ransomware groups getting in on the act
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
The FBI and Secret Service warn that the FortiBleed campaign has targeted over 400,000 Fortinet devices, locking users out and enabling ransomware attacks.
Part of the PlainSec briefing for 2026-10-07