Full Report
The FBI and Secret Service warned Fortinet users that FortiBleed, uncovered this summer, is a continuing threat. The post Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks appeared first on CyberScoop.
Analysis Summary
# Incident Report: FortiBleed Ongoing Credential Compromise Campaign
## Executive Summary
FortiBleed is an active and expanding credential compromise campaign targeting Fortinet firewalls and VPN gateways globally. The campaign, which has affected upwards of 450,000 devices, involves threat actors stealing credentials to gain administrative access, often resulting in legitimate users being locked out of their systems. This activity frequently serves as a precursor to ransomware deployment by affiliates such as INC/Lynx and Payload.
## Incident Details
- **Discovery Date:** Summer 2026 (Initial discovery); Updated alert October 6, 2026
- **Incident Date:** Ongoing (Active campaign)
- **Affected Organization:** Global Fortinet users
- **Sector:** Cross-sector (Critical Infrastructure, Government, and Private Enterprise)
- **Geography:** Global (Over 194 countries identified)
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing since Summer 2026.
- **Vector:** Exploitation of exposed Fortinet firewalls and VPN gateways.
- **Details:** Attackers utilize stolen credentials (likely harvested via previous exploits or credential stuffing) to gain unauthorized entry to the device management interfaces.
### Lateral Movement
- **Details:** Once inside the gateway, threat actors use the compromised edge device as a beachhead to move laterally into the internal network, facilitating the deployment of secondary malware.
### Data Exfiltration/Impact
- **Details:** Attackers have been observed creating unauthorized administrative accounts and changing passwords to lock out legitimate owners. The access is also sold to initial access brokers (IABs) who facilitate ransomware attacks.
### Detection & Response
- **Detection:** Identified by SOCRadar and subsequently confirmed by the FBI and U.S. Secret Service through forensic investigation and network telemetry.
- **Response actions taken:** Issuance of a joint Cybersecurity Advisory (CSA) by federal agencies; recommendations for emergency credential resets and MFA enforcement.
## Attack Methodology
- **Initial Access:** Compromised credentials targeting internet-facing Fortinet VPNs/Firewalls.
- **Persistence:** Creation of new unauthorized administration accounts.
- **Privilege Escalation:** Gaining administrative control over the firewall/gateway device.
- **Defense Evasion:** Disabling legitimate administrative accounts to prevent remediation.
- **Credential Access:** Credential compromise of existing users.
- **Discovery:** Identifying exposed edge devices via internet scanning.
- **Lateral Movement:** Using the VPN gateway as an entry point to the broader corporate network.
- **Collection:** N/A (Specific data gathering methods not detailed in article).
- **Exfiltration:** N/A.
- **Impact:** System lockout and ransomware deployment (INC/Lynx, Payload).
## Impact Assessment
- **Financial:** High potential costs associated with ransomware remediation and business downtime.
- **Data Breach:** Compromise of administrative credentials and potential downstream data theft during ransomware phases.
- **Operational:** Significant; organizations may be completely locked out of their network infrastructure, requiring manual remediation beyond standard patching.
- **Reputational:** High for affected organizations, particularly those in critical sectors.
## Indicators of Compromise
*Note: Specific indicators are actively being collected by the FBI/Secret Service.*
- **Network indicators:** Unusual traffic to/from management interfaces; unauthorized IP addresses accessing admin portals.
- **File indicators:** Creation of unauthorized local accounts on FortiOS.
- **Behavioral indicators:** Sudden password changes for admin accounts; disabling of logging or security features; lockout of legitimate administrators.
## Response Actions
- **Containment measures:** Restrict external management access to the internet.
- **Eradication steps:** Review and delete unauthorized administrative accounts.
- **Recovery actions:** Perform full credential resets across the environment; restore system access through out-of-band management if locked out.
## Lessons Learned
- **Key takeaways:** Patching alone is insufficient if credentials have already been compromised; threat actors are increasingly focusing on edge devices to bypass traditional perimeter security.
- **What could have been done better:** Earlier adoption of Multi-Factor Authentication (MFA) and restricting management interfaces from being public-facing could have mitigated the majority of the risk.
## Recommendations
- **Prevention:** Disable all internet-facing management interfaces (HTTPS/SSH) or restrict them to specific trusted IPs (VPN/Management LAN).
- **Identity Security:** Enforce Multifactor Authentication (MFA) for all VPN and administrative accounts.
- **Monitoring:** Enable and review logs specifically for lateral movement and unauthorized changes to firewall user accounts.
- **Credential Hygiene:** Enable secure credential storage and implement regular rotation policies for administrative secrets.