← All security news

FBI Warns FortiBleed Campaign Is Still Draining Fortinet Firewalls

A cracked shield leaking a drop next to a key, representing a credential-harvesting campaign against Fortinet firewalls and VPN gateways

The FBI and the U.S. Secret Service issued a joint advisory on 6 October warning that a credential-harvesting campaign researchers call FortiBleed is still active against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The operation, first documented by security researchers in June 2026, has amassed more than 86,644 working device credentials spanning 194 countries. Rather than exploiting a single software flaw, FortiBleed relies on something more mundane and arguably harder to patch away: reused or previously leaked passwords, cracked against devices that were still storing credentials with older SHA-256 hashing instead of a slower, modern algorithm built to resist large-scale cracking.

Investigators link the activity to a Russian-speaking group with reported overlaps with the INC and Lynx ransomware operations. The advisory says attackers are continuing to scan the internet for exposed Fortinet devices and test them against the stolen credential set. In some cases, victims have been locked out of their own firewalls entirely after an attacker logged in and changed or deleted the original administrator account. A locked-out firewall is a worst-case outcome for a small business: the device meant to be the first line of defence becomes something only the attacker controls, often as a precursor to a ransomware deployment rather than the end goal itself.

What this means for your business

If your business, or whoever manages your network, runs a Fortinet FortiGate firewall or SSL VPN for remote access, this week is the time to check two things. First, confirm the admin and VPN credentials on that device are not reused anywhere else — if the same password, or a close variant, appears on a personal account, an old SaaS login, or another piece of infrastructure, assume it may already be sitting in a leaked-credential list and rotate it now. Second, check whether multi-factor authentication is enforced on every account that can reach the device's admin interface or VPN portal; FortiBleed's entire method depends on a password being enough on its own.

It's also worth asking your IT provider, in plain terms, whether your organisation's VPN and firewall accounts have recently been checked against known credential-leak databases, and whether logins are being monitored for the pattern this campaign relies on — many failed attempts, from many locations, against the same account. If nobody can answer that confidently, it's a gap worth closing: a firewall nobody is watching is not meaningfully more secure than having no firewall at all.

Questions about your own setup? contact@techleetsolutions.com
Sources: FBI/Secret Service joint advisory (IC3), The Hacker News, The Register