FBI warns FortiBleed campaign is still active and locking admins out of FortiGate devices
A joint advisory from the FBI and the US agency USSS says attackers are still logging in to exposed Fortinet firewalls with harvested credentials, and in some cases remove or alter the original admin accounts.

Key points
- 1The FBI and USSS say the FortiBleed campaign against exposed FortiGate firewalls and SSL VPN gateways is still active.
- 2In some incidents attackers delete original admin accounts or change their login data, locking legitimate administrators out of their own devices.
- 3The FBI says the attack chain has served as an entry point for ransomware affiliates; INC/Lynx and Payload are named.
- 4SOCRadar counts more than 86,644 compromised devices across 194 countries and at least 12 ransomware deployments linked to the access.
- 5Advised steps include cutting internet-facing management, ending sessions, resetting credentials, phishing-resistant MFA and PBKDF2 credential storage.
Full story
The FBI and the US agency USSS have warned that FortiBleed, a credential harvesting campaign aimed at Fortinet FortiGate firewalls and SSL VPN gateways reachable from the internet, is still under way. According to SOCRadar, the joint advisory was published on October 6, 2026. The agencies said attackers keep scanning exposed Fortinet firewalls and trying credentials they had obtained earlier, as reported by The Hacker News. The advisory itself could not be reviewed for this story; its content here is based on how The Hacker News, BleepingComputer and SOCRadar describe it.
The main change is the impact on victims. After getting in, the attackers set up new administrator accounts that did not exist on the device before. In some incidents they then delete the original admin accounts or change their login data, so the legitimate IT team can no longer manage its own firewall while the intruders keep control and try to move further into the network, the FBI and USSS said according to The Hacker News and BleepingComputer. The agencies warn that recovery may take more than applying patches and resetting Fortinet credentials. SOCRadar advises defenders to make sure they have an out-of-band way to regain administrative control of edge devices.
According to the reports, the attackers get their first foothold with credentials from earlier leaks or infostealer logs, or through credential stuffing and spraying. They then pull further authentication data from compromised devices; The Hacker News describes a Go-based tool called FortigateSniffer that passively captures login traffic across 24 protocols. Credential hashes are cracked offline on a distributed GPU cluster running Hashcat and Hashtopolis. The agencies said the campaign takes advantage of reused or previously exposed credentials and of legacy SHA-256 storage on the devices. Scripts then weed out honeypots, map the organizations behind each device and rank targets by revenue and network structure. BleepingComputer reports that these details surfaced after the operators accidentally exposed their own backend server.
The FBI said that “the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates”. According to SOCRadar, the advisory lists those downstream affiliates as currently including INC/Lynx and Payload ransomware. The operator is suspected of working as an initial access broker that bundles working VPN configurations and target lists for sale to other criminals. SOCRadar, which first documented FortiBleed in June, counts more than 86,644 compromised devices across 194 countries and stresses that this figure covers confirmed compromises, not an exposure estimate. The firm told The Hacker News it has confirmed at least 12 ransomware deployments that came from this access, with hundreds of endpoints encrypted. SOCRadar CISO Ensar Seker said the advisory backs the firm’s view that “FortiBleed should be treated as an active access operation, not as a one-time credential leak”.
The recommended steps go beyond resetting credentials. According to the reports, they include limiting or removing management access from the internet, ending all active VPN and admin sessions, resetting Fortinet VPN and admin credentials, enforcing phishing-resistant multi-factor authentication, comparing configurations with a known-good baseline and checking firewall, VPN, authentication and domain controller logs for unauthorized changes. Administrator credentials should be stored with PBKDF2 rather than legacy SHA-256 hashes, which attackers can crack offline. SOCRadar says the advisory also points to SSH, which actors may have abused where the port was left open, and to rogue REST API credentials that persist after a reset. Organizations that spot a possible compromise are told to isolate affected devices, collect logs and artifacts, and report the incident to the FBI and USSS. Ben Bernstein of Huntress said: “When you no longer have access to your own firewall, you cannot just apply a software patch and move on”.
Why it matters
Many organizations treat a patch or a credential reset as the fix for a compromised edge device. As the sources describe the advisory, that is not enough once attackers hold their own admin accounts or have locked the owners out, and Huntress says affected organizations may have to factory reset and rebuild the hardware. SOCRadar warns that devices breached months ago remain in the attackers’ inventory and that the list of ransomware customers can grow over time. The advisory text itself could not be reviewed for this story, so its details rely on the cited reports.
Timeline
· Published
Topics#FortiBleed#Fortinet#FBI#Ransomware#Initial access
Sources
This story draws on the following sources. Read them for full context.
- 1BleepingComputer · News reportFBI: Ongoing FortiBleed attacks lock out FortiGate VPN adminswww.bleepingcomputer.com
- 2The Hacker News · News reportFBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentialsthehackernews.com
- 3SOCRadar · AnalysisFortiBleed Is Still Active, Locking Organizations Outsocradar.io



