Threats · 2h ago

FortiBleed Keeps Feeding on Fortinet Logins

The FBI and U.S. Secret Service say FortiBleed is still targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, and that the campaign has already collected more than 86,644 working device credentials across 194 countries. The agencies say attackers are still scanning exposed devices with previously stolen logins.

The campaign starts with reused or leaked passwords, then uses a FortiGate sniffer to capture authentication traffic and harvest password hashes from the device itself. Those hashes are cracked offline in bulk, so the operation keeps finding new working logins without staying online for long, and stolen session cookies can keep access alive after a reset.

For any network that uses FortiGate as the front door, the exposure is not just the password that was reused first; it is the firewall account, the VPN session, and whatever the gateway can reach once those credentials are cracked and reused. A reset-only response can miss already-harvested sessions and accounts that were recovered offline.

Timeline

Sources

6 sources covering this story

Entities

Vendor digest: Fortinet

Part of the PlainSec briefing for 2026-10-07

Editions

Related stories