The FBI has issued a warning that the FortiBleed campaign targeting Fortinet FortiGate firewalls and SSL VPN gateways remains active, with attackers locking legitimate administrators out of their own devices.
According to the FBI, threat actors gain initial access to exposed endpoints using previously leaked credentials, infostealer logs, credential stuffing, or password spraying. Once inside, they extract additional authentication data from the compromised device and run it through a distributed GPU cluster using Hashcat and Hashtopolis to crack password hashes offline.
In some cases, attackers create new administrator accounts and then delete the legitimate ones or change their passwords, cutting off victim access entirely. From there, they establish persistence and attempt to move laterally across the network.
A leak with long legs
FortiBleed traces back to a credentials leak discovered in June, when attackers inadvertently exposed a server containing usernames and plaintext passwords tied to 73,932 firewall URLs spanning 194 countries. In July, researchers at SOCRadar linked the campaign to the INC and Lynx ransomware operations after gaining access to both groups’ negotiation panels on infrastructure used in the attacks. SOCRadar’s latest tally puts the number of compromised devices at 86,644.
The FBI notes that FortiBleed has become an established initial entry point for ransomware affiliates, specifically naming INC/Lynx and Payload ransomware as beneficiaries. Exposure of the attacker’s backend server revealed automated scanning scripts for FortiGate SSL VPN portals, the GPU password-cracking setup, and tooling to validate stolen credentials, filter out honeypots, and prioritize targets by revenue and network structure. Working VPN configurations and target lists were also found, suggesting the operator was packaging access for resale.
Remediation guidance
The FBI cautions that patching and resetting passwords alone may not be sufficient to remediate an incident. Recommended steps include:
- Restricting external access to management interfaces
- Terminating all active VPN sessions
- Enforcing multi-factor authentication
- Reviewing logs for unauthorized account changes and suspicious activity
- Enforcing PBKDF2 for administrator password storage instead of legacy SHA-256 hashing, which attackers can crack offline far more easily
Organizations running FortiGate devices with exposed admin or VPN portals should treat this as an active, ongoing threat rather than a historical incident tied to the June leak.
