VMTech
Discuss a project →

FBI says FortiBleed campaign continues to target Fortinet gateways

FBI says FortiBleed campaign continues to target Fortinet gateways

The U.S. Federal Bureau of Investigation and U.S. Secret Service have warned that the FortiBleed credential-harvesting campaign remains active against internet-facing Fortinet FortiGate firewalls and SSL virtual private network gateways. The Russian-speaking operation had obtained more than 86,644 working device credentials across 194 countries as of June 19, 2026.

The agencies said attackers are continuing to scan exposed Fortinet firewalls with compromised credentials collected earlier. The activity relies on reused or leaked passwords and legacy SHA-256 password storage, enabling authentication data to be harvested and cracked at scale.

A multi-stage route from exposed portals to persistent access

FortiBleed was first documented by SOCRadar and Hudson Rock in June 2026. Its five-stage operation begins with broad reconnaissance for exposed portals, followed by credential stuffing and password spraying using data from leak dumps and infostealer logs.

Once access is obtained, operators deploy the Go-based FortigateSniffer tool. It passively intercepts authentication traffic across 24 protocols and collects credentials and password hashes. Those hashes are sent to a GPU-accelerated cracking cluster using Hashmat and Hashtopolis for offline cracking.

Validated credentials can then be used for lateral movement, Active Directory enumeration, Kerberos validation and SMB authentication. In the final stage, the actors exfiltrate data from network shares and use stolen session cookies to retain authenticated access.

Account changes can hinder incident response

The FBI and USSS said cracked credentials are enriched, sorted and validated, while scripts filter honeypots, map organisations and prioritise targets by revenue and network structure. The agencies also observed the creation of new administrative accounts on compromised firewalls to establish persistence.

That persistence can disrupt recovery. Threat actors may change or delete passwords for original accounts, potentially locking organisations out of their Fortinet devices. They can also delete existing accounts while moving laterally and searching for privileged access.

Recommended containment steps

CISA had already urged Fortinet customers to enable phishing-resistant authentication, terminate active SSL VPN and administrative sessions, reset Fortinet VPN and administrator passwords, use PBKDF2 to store administrator credentials, and examine logs for suspicious activity.

If a compromise is suspected, the FBI and USSS advise isolating affected devices, collecting relevant artifacts and logs, reporting the incident to both agencies, and applying suitable countermeasures. For businesses, the immediate implication is to treat internet-exposed FortiGate and SSL VPN systems as priority assets: verify account integrity, end active sessions and preserve evidence before access changes complicate containment.

#cybersecurity#fortinet#vpnsecurity#incidentresponse
Open analytics
On the site 1 views
min read 3 07.10.2026
Instagram

FBI says FortiBleed campaign continues to target Fortinet gateways

Open the post on Instagram ↗