Skip to content
TrustList
News

FBI warns FortiBleed is still hitting exposed FortiGate VPNs

Editorial

By TrustList Editorial

SOCRadar verified more than 86,644 compromised devices in 194 countries. The agencies say changing passwords is not enough, because attackers add admin accounts and can delete existing ones.

About FBI warns FortiBleed is still hitting exposed FortiGate VPNs

FBI warns FortiBleed is still hitting exposed FortiGate VPNs

6 October 2026: The FBI and the US Secret Service say FortiBleed, an active credential-compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, is continuing and has locked some organisations out of their own devices. The joint advisory, JCSA-20261006-01, carries no CVE number and no fixed software version: the campaign uses reused or leaked passwords and a legacy SHA-256 password hash format, so the remedy is configuration and credential work rather than a patch.

The advisory cites SOCRadar, which verified more than 86,644 compromised devices across 194 countries. The agencies describe a credential-harvesting and access-broker operation whose workings became visible after the operators exposed their own backend server. Attackers scanned for exposed FortiGate SSL VPN portals, ran credential stuffing and password spraying from earlier Fortinet leak dumps and infostealer logs, and fed stolen hashes into a GPU cluster that cracked them offline. Valid logins were then sorted by victim revenue and network structure, and the access was packaged and sold.

After getting in, the operators create new administrator accounts on the firewall. In some cases they delete or change the original accounts, which is what produces lockouts. The advisory lists account names seen on victim devices, among them forticloud-sync, fgtsecure, itadmin and support_fortinet, and several IP addresses with the dates they were observed between June and July 2026.

The agencies report that initial access brokers using this chain have passed access to ransomware affiliates, currently including INC/Lynx and Payload.

The mitigations it lists:

  • limit management access to trusted hosts, better a local-in policy, best no internet-facing administration at all
  • end every active admin and VPN session, then reset all VPN and administrator passwords
  • require phishing-resistant multifactor authentication on all remote access and administrative accounts
  • review every firewall account and the firewall, VPN, authentication and domain controller logs for unfamiliar users and configuration changes
  • store administrator credentials with PBKDF2 and remove weaker legacy hashes, following Fortinet's guidance for FortiOS 7.2.11 and later

The advisory advises vetting the listed indicators before blocking on them. It is marked TLP:CLEAR, so it can be shared freely.

Company profile on TrustList: Fortinet

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy