Sunday, October 11, 2026
News

FBI warns FortiBleed attackers are locking companies out of their own FortiGate firewalls

A joint advisory issued on October 6 says the operators sell network access to ransomware groups. No CVE is involved, so a firmware update will not evict them.

A network switch with Ethernet cables plugged inUser_Pascal / Unsplash
Photo: User_Pascal / Unsplash

The FBI and the US Secret Service issued a joint advisory on October 6 warning that FortiBleed, a months-long campaign against Fortinet firewalls, has escalated. The attackers now create their own administrator accounts on compromised FortiGate devices, then delete the original accounts or change their passwords. Owners find they can no longer log in to their own firewalls.

Security firm SOCRadar estimates that more than 86,000 FortiGate devices in 194 countries have been compromised, out of more than 430,000 the operation targeted, Cybersecurity Dive reported. CloudSEK says more than half of the compromised devices are in India, the United States, Taiwan, Mexico and Turkey. Victims span all 16 US critical infrastructure sectors.

How the attackers get in

FortiBleed is not built on a software flaw. The advisory lists no CVE. The operators collect working credentials and use them:

  • Credential stuffing and password spraying, using passwords from earlier Fortinet leak dumps and from infostealer logs.
  • Dumping FortiOS user databases and session tokens from devices they already control.
  • Cracking stolen password hashes offline on a GPU cluster running Hashcat and Hashtopolis. The advisory says older SHA-256 password storage on FortiOS makes this easier.

Cybersecurity Dive also reports that the group uses a custom "FortiGate sniffer" written in Go to capture authentication traffic.

The people behind it act as an initial access broker. They sort the stolen access by the victim's revenue and network layout and sell it on. The FBI links the campaign to the Payload ransomware operation, and SOCRadar links it to INC and Lynx.

Fortinet said in a June advisory that it believed the attackers were reusing credentials stolen in earlier incidents and brute-forcing devices with weak passwords and no multifactor authentication.

Why patching is not enough

Because the attackers log in with valid credentials, a firmware upgrade leaves them in place. Their extra admin accounts, VPN users and API keys survive a reboot. Clearing them out means resetting credentials and checking the configuration line by line.

What IT teams should do

These steps follow the order in the FBI and Secret Service advisory.

  1. Take FortiGate management off the internet. The advisory ranks the options: trusted hosts (good), a local-in policy (better), no internet-facing admin access at all (best).
  2. End every admin and VPN session, then reset all Fortinet VPN and administrator passwords, starting with internet-facing devices.
  3. Turn on phishing-resistant multifactor authentication for every remote access and admin account.
  4. Compare the current list of firewall and VPN users with a known-good configuration backup. The advisory names account names seen on compromised devices, including forticloud-tech, support_fortinet, forti_support2, fgtsecure, adminsslvpn and Technical_support.
  5. Review firewall, VPN, authentication and domain controller logs for unusual logins, new accounts and configuration changes.
  6. Store admin passwords with PBKDF2 (FortiOS 7.2.11 and later) and remove weaker legacy hashes.
  7. Review REST API keys. Delete any you don't recognize and reissue the rest.

If you are already locked out of a device, the FBI advises isolating it, taking it offline if needed and collecting logs before rebuilding. The advisory includes IP addresses used by the operators, but warns that cloud addresses get reassigned, so check them against current data before blocking.

Sources