Full Report
Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement says.
Analysis Summary
# Incident Report: Campaign "FortiBleed" Credential Harvesting
## Executive Summary
FortiBleed is a massive, ongoing global credential-stealing campaign targeting over 86,000 internet-facing Fortinet FortiGate firewalls and VPN gateways. Threat actors utilize automated scripts and credential stuffing to harvest authentication data, which is then sold to ransomware affiliates or used to establish persistent backdoors. The campaign has impacted organizations across 194 countries, serving as a primary entry point for major ransomware groups.
## Incident Details
- **Discovery Date:** July 2026 (Initial reporting by security firms)
- **Incident Date:** Ongoing (Warnings escalated October 6-7, 2026)
- **Affected Organization:** Multiple (86,000+ devices)
- **Sector:** Cross-sector (including Government, Healthcare, and Finance)
- **Geography:** Global (194 countries identified)
## Timeline of Events
### Initial Access
- **Date/Time:** Campaign active for several months prior to October 2026.
- **Vector:** Credential Stuffing and Password Spraying.
- **Details:** Attackers used automated tools to scan for exposed FortiGate SSL VPN portals and attempted to authenticate using previously leaked or reused credentials.
### Lateral Movement
- **Techniques:** Once the firewall was compromised, attackers identified internal network structures and moved laterally to high-value targets, specifically prioritizing organizations based on revenue.
### Data Exfiltration/Impact
- **Impact:** Massive harvesting of authentication artifacts. Over 12 organizations were confirmed encrypted by ransomware (INC/Lynx and Payload groups) via this vector. U.K. government official email accounts were also targeted.
### Detection & Response
- **Discovery:** Law enforcement gained visibility after attackers accidentally exposed their own backend server, revealing their internal workflow, datasets, and tooling.
- **Response actions taken:** FBI, Secret Service, CISA, and NCSC (UK) issued joint advisories. Automated alerts were sent to affected organizations.
## Attack Methodology
- **Initial Access:** Valid Accounts (Credential Stuffing/Password Spraying) targeting SSL VPN portals.
- **Persistence:** Creation of new administrative accounts on firewall devices.
- **Privilege Escalation:** Manipulation of firewall administrative settings.
- **Defense Evasion:** Use of AI tools to bypass model safety controls and security filters.
- **Credential Access:** Automated harvesting and "cracking" of authentication data at scale.
- **Discovery:** Internet-wide scanning for exposed FortiGate devices; sorting victims by revenue.
- **Lateral Movement:** Exploitation of established VPN sessions to reach internal assets.
- **Collection:** Gathering large datasets of valid credentials and network metadata.
- **Exfiltration:** Transfer of harvested credentials to attacker-controlled backend servers.
- **Impact:** Account lockout (changing passwords), disabling of accounts, and deployment of ransomware.
## Impact Assessment
- **Financial:** Significant (Access sold to ransomware affiliates; potential for multi-million dollar ransoms).
- **Data Breach:** Compromise of administrative credentials for 86,000+ gateways.
- **Operational:** High (Users locked out of systems; business disruption due to ransomware).
- **Reputational:** High (Compromise of government officials and global enterprises).
## Indicators of Compromise
- **Network indicators:** Scanning activity originating from specific backend infrastructure (Note: Specific IPs are mentioned as recovered from the leaked server tooling).
- **File indicators:** Automated scripts used for credential validation.
- **Behavioral indicators:** Creation of unauthorized new admin accounts; logins from unusual geographic locations; sudden disabling of legitimate admin accounts.
## Response Actions
- **Containment measures:** Terminating all active admin VPN sessions.
- **Eradication steps:** Deleting unauthorized accounts and resetting all administrative credentials.
- **Recovery actions:** Restoring access to locked-out administrators and reviewing firewall logs for secondary backdoors.
## Lessons Learned
- **Key takeaways:** Device patching alone is insufficient if credentials have already been harvested; attackers are increasingly using AI to bypass traditional security controls.
- **Improvement areas:** Organizations failed to notice the creation of new, unauthorized administrative accounts on perimeter devices.
## Recommendations
- **Restrict Management:** Disable internet-facing administration or restrict it to specific trusted IP ranges.
- **Multi-Factor Authentication (MFA):** Enforce MFA for all VPN and administrative accounts to mitigate credential stuffing.
- **Account Auditing:** Regularly audit all accounts on Fortinet devices for unauthorized additions.
- **Credential Hygiene:** Implement strict password policies and monitor for leaked corporate credentials on the dark web.