FortiBleed: FBI says 86,000+ Fortinet devices compromised
The FBI and the US Secret Service have issued their own warning about FortiBleed, a long-running credential theft campaign aimed at Fortinet FortiGate firewalls and VPN gateways. According to the agencies, more than 86,000 internet-facing devices have been compromised.
The advisory, published on Tuesday, says the attacks have continued for months and have reached organizations in 194 countries. FortiBleed does not depend on a single software flaw. It relies on credentials that were reused or leaked, which the attackers use to "harvest and crack authentication data at scale."
"Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials," the agencies said.
Lockouts and ransomware
The agencies warned that patching alone will not fix the problem. "Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets. In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates."
Initial access brokers, criminals who break into networks and then sell that access to others, are also involved. The advisory says they offer footholds to affiliates of the INC/Lynx and Payload ransomware operations.
An exposed backend server revealed the workflow
Security companies and law enforcement learned how the operation worked after the attackers exposed their own backend server. That mistake made the group's internal processes visible.
"The recovered tooling and datasets provide a rare, end-to-end view of how the operators identified targets, validated stolen credentials, and expanded access inside victim networks," the agencies explained.
The recovered data shows a structured process:
- the attackers scanned the internet for exposed FortiGate SSL VPN portals
- automated scripts identified which devices could be reached
- credential stuffing and password spraying attacks collected large volumes of credentials and authentication artifacts
- stolen credentials were sorted, validated and organized by the victim organization's revenue or network structure
- new accounts were created on compromised firewalls so the attackers could keep their access
The access was then either sold to other criminals or used directly by the operators.
Months of earlier warnings
The campaign is not new to researchers. In July, SOCRadar published a detailed study showing how affiliates of the INC and Lynx groups took part in FortiBleed. An internal tracking file showed more than 20 affiliates in defined roles, scanning thousands of FortiGate portals across more than 150 countries. At least 12 organizations were breached and had their systems encrypted with ransomware.
SOCRadar also found that the group spent heavily on artificial intelligence tools, including tools that helped them bypass model safety controls.
Three months ago, the Cybersecurity and Infrastructure Security Agency (CISA), the US federal agency responsible for civilian cyber defense, issued its own warning together with officials in the UK. Russian hackers allegedly used the campaign to break into email accounts belonging to UK government officials.
What the agencies recommend
The FBI and Secret Service advise organizations to review every Fortinet account and confirm that each one is legitimate. External management of the devices should be restricted, or internet-facing administration removed entirely. Credentials should be reset and all active admin VPN sessions terminated.
Our Take
The size of FortiBleed is notable, but its method is ordinary. It suggests that many attackers no longer need a zero-day to get into edge devices. Valid passwords collected from earlier leaks can be enough, and they work against fully patched systems. For defenders, this changes the order of work. Applying vendor updates, such as those for the recent FortiMail zero-day, remains essential, but it has to come together with checks for unknown admin accounts, credential resets and limits on who can reach management interfaces.
The campaign also fits a wider pattern of attackers targeting VPN and remote access appliances, as seen with recent issues affecting SonicWall SMA 1000 gateways and Citrix NetScaler. These devices sit at the network edge and often give broad internal access, which makes them attractive to access brokers and ransomware affiliates alike.
It is worth watching whether the exposed backend data leads to arrests or further attribution, and whether ransomware groups beyond INC/Lynx and Payload start using the stolen access. Organizations that found and removed rogue accounts months ago may also want to check again, since the agencies say scanning with previously stolen credentials is still ongoing.
