{"id":460,"date":"2026-10-08T19:49:41","date_gmt":"2026-10-08T19:49:41","guid":{"rendered":"https:\/\/managedt.com\/blog\/fortibleed-fbi-warning-fortinet-credentials\/"},"modified":"2026-10-08T19:49:42","modified_gmt":"2026-10-08T19:49:42","slug":"fortibleed-fbi-warning-fortinet-credentials","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/fortibleed-fbi-warning-fortinet-credentials\/","title":{"rendered":"FBI Warns FortiBleed Campaign Still Active After 86,644 Fortinet Credentials Harvested"},"content":{"rendered":"<h2>What FortiBleed means for organizations running Fortinet firewalls<\/h2>\n<p>Organizations running internet-facing Fortinet FortiGate firewalls and SSL VPN gateways can act now to stop a credential-harvesting campaign that the FBI and U.S. Secret Service confirm is still active. The same advisory warns that more than 86,644 working device credentials have been collected across 194 countries, giving attackers a ready supply of working logins for SSL VPN and administrative access.<\/p>\n<p>The campaign, tracked as FortiBleed, exploits reused and leaked credentials along with legacy SHA-256 password storage, and it lets threat actors crack authentication data at scale. A flagged risk is that some victims may lose access to their own Fortinet devices if attackers delete or change the original account passwords after creating new administrative accounts to hold persistence.<\/p>\n<h2>What the FBI and USSS advisory says<\/h2>\n<p>The joint advisory states that attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials. It traces the activity to a five-stage operation that runs widespread reconnaissance, gains access through credential stuffing and password spraying against data drawn from prior leak dumps and infostealer logs, then deploys a Go-based tool called FortigateSniffer. FortigateSniffer passively intercepts authentication traffic across 24 protocols to harvest credentials and password hashes.<\/p>\n<p>Harvested password hashes are then routed to a GPU-accelerated cracking cluster using Hashmat and Hashtopolis for offline cracking. With verified credentials in hand, attackers move deeper into victim environments, conduct enumeration, and run additional password spraying to identify privileged accounts. New administrative accounts are created on the firewall to maintain persistence, and in some cases existing accounts are deleted, locking the real IT team out of the appliance.<\/p>\n<p>The advisory also notes that cracked credentials are enriched, sorted, and validated, with scripts filtering out honeypots, mapping organizations, and prioritizing high-value targets based on revenue and network structure.<\/p>\n<h2>Scale, origin, and ties to ransomware groups<\/h2>\n<p>FortiBleed was first documented by SOCRadar and Hudson Rock in June 2026. As of June 19, 2026, the operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries. The advisory describes the actors as a Russian-speaking operation believed to function as an initial access broker that packages stolen information and sells it to downstream threat actors.<\/p>\n<p>Operator overlaps have tied FortiBleed access to INC and Lynx ransomware operations, indicating that the access is being abused for ransomware deployment. Threat intelligence from SOCRadar has confirmed at least 12 ransomware deployments stemming from this access, resulting in hundreds of endpoints getting encrypted, and the same access has been supplied to Payload ransomware affiliates, evidence the operation is financially motivated and tied to a broader ransomware supply chain.<\/p>\n<h2>What CISA and the FBI recommend<\/h2>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging Fortinet customers with FortiGate appliances to take these steps:<\/p>\n<ul>\n<li>Enable phishing-resistant authentication.<\/li>\n<li>Terminate active SSL VPN and administrative sessions.<\/li>\n<li>Reset Fortinet VPN and administrative passwords.<\/li>\n<li>Use the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials.<\/li>\n<li>Review logs for signs of suspicious activity.<\/li>\n<\/ul>\n<p>If potential compromise is detected, the FBI and USSS recommend isolating the affected devices, collecting necessary artifacts and logs, reporting the incident to the FBI and USSS, and applying relevant countermeasures to mitigate the threat.<\/p>\n<h2>Commonly compromised account names to audit for<\/h2>\n<p>The advisory lists account names frequently seen on compromised Fortinet devices. Reviewing local and API accounts against this list is a fast way to spot unauthorized additions:<\/p>\n<ul>\n<li>adminin<\/li>\n<li>fortiAdmin<\/li>\n<li>forticloud-sync<\/li>\n<li>admin<\/li>\n<li>fgtsecure<\/li>\n<li>pakedge<\/li>\n<li>forticloud-tech<\/li>\n<li>districtadmin<\/li>\n<li>system_config<\/li>\n<li>gttadmin<\/li>\n<li>roadmin<\/li>\n<li>itadmin<\/li>\n<li>Technical_support<\/li>\n<li>adminsslvpn<\/li>\n<li>IT_Manager<\/li>\n<li>my_admin<\/li>\n<li>support_fortinet<\/li>\n<li>fgtsec<\/li>\n<li>forti_support2<\/li>\n<\/ul>\n<h2>Why exposure does not expire<\/h2>\n<p>The core lesson in the advisory is that exposed credentials do not become harmless with age. If they remain valid, or if attackers have already created persistent accounts on the appliance, they can keep providing an entry point months after the original harvesting activity. Treating possible exposure as a compromise scenario, restricting external management, terminating active sessions, rotating administrative and VPN credentials, enforcing phishing-resistant MFA, and investigating downstream activity, is a stronger response than relying on patching alone.<\/p>\n<p>Targeting edge devices like VPNs and firewalls is a familiar pattern, but this campaign stands out for the gap between silent initial access and aggressive takeover. Attackers are stealing configuration files, cracking password hashes offline, and logging in without generating a single failed login alert. Once inside, they change administrator passwords, lock the IT team out of the equipment, and hand access to ransomware groups. When an organization loses access to its own firewall, a software patch is not enough, and a physical factory reset and hardware rebuild may be required before encryption begins.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is FortiBleed?<\/h3>\n<p>FortiBleed is a credential harvesting campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It was first documented in June 2026 and is estimated to have collected more than 86,644 working device credentials across 194 countries.<\/p>\n<h3>What should organizations do right now to protect Fortinet devices?<\/h3>\n<p>Enable phishing-resistant authentication, terminate active SSL VPN and administrative sessions, reset Fortinet VPN and administrative passwords, store administrator credentials using PBKDF2, and review logs for suspicious activity. Audit local and API accounts for unauthorized additions and remove internet-facing administration interfaces where possible.<\/p>\n<h3>How is FortiBleed connected to ransomware?<\/h3>\n<p>Operator overlaps tie FortiBleed-derived access to INC and Lynx ransomware operations, and the same access has been supplied to Payload ransomware affiliates. At least 12 ransomware deployments have been confirmed from this access, with hundreds of endpoints encrypted.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is FortiBleed?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"FortiBleed is a credential harvesting campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It was first documented in June 2026 and is estimated to have collected more than 86,644 working device credentials across 194 countries.\"}},{\"@type\":\"Question\",\"name\":\"What should organizations do right now to protect Fortinet devices?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Enable phishing-resistant authentication, terminate active SSL VPN and administrative sessions, reset Fortinet VPN and administrative passwords, store administrator credentials using PBKDF2, and review logs for suspicious activity. Audit local and API accounts for unauthorized additions and remove internet-facing administration interfaces where possible.\"}},{\"@type\":\"Question\",\"name\":\"How is FortiBleed connected to ransomware?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Operator overlaps tie FortiBleed-derived access to INC and Lynx ransomware operations, and the same access has been supplied to Payload ransomware affiliates. At least 12 ransomware deployments have been confirmed from this access, with hundreds of endpoints encrypted.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/thehackernews.com\/2026\/10\/fbi-warns-fortibleed-remains-active.html\" target=\"_blank\" rel=\"nofollow noopener\">thehackernews.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The FBI and USSS say the FortiBleed campaign targeting Fortinet FortiGate firewalls remains active, with 86,644 device credentials already harvested worldwide.<\/p>\n","protected":false},"author":3,"featured_media":459,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-460","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=460"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/460\/revisions"}],"predecessor-version":[{"id":461,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/460\/revisions\/461"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/459"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}