Last updated: October 8, 2026 at 8:36 AM UTC
All 909 Vulnerability 368 Breach 144 Threat 390 Defense 7
Tag: ransomware-access (1 article)Clear

FBI warns FortiBleed credential campaign stays active and locks administrators out of Fortinet VPN gateways

The FBI and Secret Service warned that FortiBleed, a credential-harvesting campaign against internet-facing FortiGate firewalls and SSL VPN gateways, remains active. The Russian-speaking operation uses credential stuffing and password spraying, then deploys a Go tool called FortigateSniffer to intercept authentication traffic, exploiting reused or leaked credentials and legacy SHA-256 password storage rather than a software flaw. It had collected more than 86,644 working device credentials across 194 countries as of June. Attackers create new admin accounts and reuse session cookies for persistence, and some victims are locked out when original accounts are changed or deleted. Operator overlaps link it to INC and Lynx ransomware.

Check
Review internet-facing Fortinet firewalls for unfamiliar admin accounts, reset VPN and admin passwords, terminate active sessions, and enable phishing-resistant authentication per the FBI and CISA guidance.
Affected
Internet-facing FortiGate firewalls with reused, leaked, or weakly stored credentials let attackers validate logins, add admin accounts, hijack sessions, and lock out legitimate administrators.
Fix
Reset VPN and admin credentials, remove rogue accounts such as fortiAdmin or forticloud-sync, store credentials with PBKDF2, enable strong authentication, and report incidents to the FBI and Secret Service.