Full Report
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]
Analysis Summary
# Incident Report: Ongoing FortiBleed Credential Harvesting and Ransomware Enablement
## Executive Summary
The FBI has issued a warning regarding "FortiBleed," an ongoing campaign targeting Fortinet FortiGate firewalls and SSL VPN gateways via harvested credentials. Attackers leverage leaked logs and automated cracking clusters to gain administrative access, subsequently locking out legitimate users and facilitating ransomware deployments. The impact is global, with over 86,000 devices compromised to serve as entry points for groups like INC/Lynx and Payload ransomware.
## Incident Details
- **Discovery Date:** June 2026 (Initial leak discovery)
- **Incident Date:** Ongoing (Reported October 7, 2026)
- **Affected Organization:** 86,644+ compromised devices globally
- **Sector:** Cross-sector (Targeting high-revenue organizations)
- **Geography:** Global (194 countries)
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing since at least June 2026.
- **Vector:** Credential-based attacks (Leaked logs, credential stuffing, password spraying).
- **Details:** Threat actors use previously leaked plaintext credentials or logs from infostealers to access FortiGate SSL VPN portals.
### Lateral Movement
- **Details:** Once administrative access to the firewall is secured, attackers establish persistence and attempt to move laterally into the internal corporate environment.
### Data Exfiltration/Impact
- **Details:** Attackers extract authentication data and configuration files from firewalls. Legitimate administrators are frequently locked out of their own devices through account deletion or password changes.
### Detection & Response
- **Discovery:** An attacker accidentally exposed a backend server, revealing the campaign's scale, tooling, and datasets.
- **Response Actions:** FBI and SOCRadar tracking; public advisories issued to affected organizations.
## Attack Methodology
- **Initial Access:** Use of leaked credentials, infostealer logs, and brute-force methods (stuffing/spraying).
- **Persistence:** Creation of new unauthorized administrator accounts.
- **Privilege Escalation:** Gaining full administrative control over FortiGate devices.
- **Defense Evasion:** Use of scripts to filter out honeypots and validate credentials before active use.
- **Credential Access:** Extraction of password hashes from compromised devices; offline cracking using a distributed GPU cluster (Hashcat/Hashtopolis).
- **Discovery:** Automated scanning of FortiGate portals and scripts to identify target organization revenue and network structure.
- **Lateral Movement:** Transitioning from the VPN gateway into the internal network.
- **Collection:** Packaging compromised VPN configurations and target lists for sale or use.
- **Exfiltration:** Theft of device configuration data and authentication hashes.
- **Impact:** Administrative lockout and serving as an entry point for ransomware affiliates (INC/Lynx, Payload).
## Impact Assessment
- **Financial:** High potential for loss due to ransomware demands; targeting of high-revenue organizations.
- **Data Breach:** Exposure of VPN configurations and administrative credentials for over 86,000 devices.
- **Operational:** Significant disruption due to administrators being locked out of critical networking hardware.
- **Reputational:** Public exposure of vulnerable infrastructure across 194 countries.
## Indicators of Compromise
- **Network:** Scanning activity originating from distributed GPU cluster IPs (specific IPs not provided in text).
- **File:** Tools including Hashcat and Hashtopolis on backend servers.
- **Behavioral:** Unauthorized creation of admin accounts; deletion of legitimate admin accounts; unexpected VPN session activity; high-volume login attempts.
## Response Actions
- **Containment:** Restrict external access to management interfaces.
- **Eradication:** Terminate all active VPN sessions and delete unauthorized accounts.
- **Recovery:** Perform a full password reset for all users; patch devices to the latest firmware.
## Lessons Learned
- **Credential Hygiene:** Plaintext password storage and weak hashing (SHA-256) are insufficient against modern GPU cracking clusters.
- **Visibility:** The exposure of the attacker's backend server was the primary catalyst for understanding the campaign's full scope.
- **MFA Necessity:** Single-factor VPN access remains the primary facilitator for these large-scale breaches.
## Recommendations
- **Enforce MFA:** Mandatory Multi-Factor Authentication for all VPN and administrative access.
- **Upgrade Hashing:** Enforce PBKDF2 for administrator password storage on Fortinet devices.
- **Zero Trust:** Restrict administrative interface access to specific, trusted internal IPs only.
- **Log Monitoring:** Regularly review audit logs for unauthorized configuration changes or account creations.
- **Session Management:** Implement strict session timeouts and monitor for concurrent logins from disparate geographies.