Full Report
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
Analysis Summary
# Incident Report: FortiBleed Credential Harvesting Campaign
## Executive Summary
The FBI and USSS have issued a joint warning regarding "FortiBleed," an ongoing Russian-speaking credential harvesting campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The attackers exploit reused credentials and legacy SHA-256 password storage to compromise devices, having successfully netted over 86,644 sets of credentials across 194 countries. The operation likely serves as an initial access broker for ransomware groups such as INC and Lynx.
## Incident Details
- **Discovery Date:** June 2026 (Initial documentation by SOCRadar and Hudson Rock)
- **Incident Date:** Ongoing (Confirmed active as of October 7, 2026)
- **Affected Organization:** Global Fortinet customers
- **Sector:** Multi-sector (Global targets)
- **Geography:** 194 countries worldwide
## Timeline of Events
### Initial Access
- **Date/Time:** Q2 2026 – Present
- **Vector:** Credential Stuffing and Password Spraying
- **Details:** Attackers scan for exposed portals and attempt access using leaked credentials from prior data dumps and infostealer logs.
### Lateral Movement
- Once the firewall is compromised, attackers perform Active Directory (AD) enumeration, Kerberos validation, and SMB authentication to move deeper into the internal network.
### Data Exfiltration/Impact
- Sensitive data is exfiltrated from internal network shares. Stolen session cookies are utilized to bypass authentication for persistent access.
### Detection & Response
- **Discovery:** Identified via security research by SOCRadar/Hudson Rock; escalated by FBI, USSS, and CISA.
- **Response Actions:** Federal agencies issued a Joint Cybersecurity Advisory (CSA) urging password resets and the adoption of stronger encryption algorithms (PBKDF2).
## Attack Methodology
- **Initial Access:** Credential stuffing/password spraying against internet-facing VPNs/firewalls.
- **Persistence:** Creation of new administrative accounts on the firewall; use of stolen session cookies.
- **Privilege Escalation:** Harvesting high-privilege credentials via `FortigateSniffer`.
- **Defense Evasion:** Filtering out honeypots during the reconnaissance phase to avoid detection.
- **Credential Access:** Deployment of **FortigateSniffer** (Go-based tool) to intercept traffic; offline cracking of SHA-256 hashes using GPU clusters (Hashcat/Hashtopolis).
- **Discovery:** Identifying high-value targets based on corporate revenue and network structure.
- **Lateral Movement:** AD enumeration and SMB authentication.
- **Collection:** Intercepting authentication traffic across 24 protocols.
- **Exfiltration:** Theft of sensitive data from network shares.
- **Impact:** Potential lockout of legitimate administrators and downstream ransomware deployment (INC/Lynx).
## Impact Assessment
- **Financial:** Potential for significant ransom demands from downstream ransomware operators.
- **Data Breach:** Over 86,644 working device credentials stolen.
- **Operational:** Organizations may be locked out of their own security appliances if attackers delete original accounts.
- **Reputational:** High, given the scale of the compromise across nearly 200 countries.
## Indicators of Compromise
### Behavioral Indicators
- Creation of unauthorized accounts with names such as:
- `adminin`
- `fortiAdmin`
- `fgtsecure`
- `system_config`
- `support_fortinet`
- Unexpected administrative sessions originating from unknown IPs.
- Deletion of legitimate administrative accounts.
## Response Actions
- **Containment:** Isolate affected FortiGate appliances and terminate all active SSL VPN/admin sessions.
- **Eradication:** Delete unauthorized administrative accounts and scan for the `FortigateSniffer` tool.
- **Recovery:** Perform a global password reset for all VPN and administrative users.
## Lessons Learned
- **Legacy Weakness:** The use of legacy SHA-256 for password storage significantly lowered the barrier for offline cracking.
- **Credential Hygiene:** The success of the campaign relied heavily on credential reuse from unrelated historical leaks.
- **MFA Importance:** The absence of phishing-resistant Multi-Factor Authentication (MFA) on edge devices allowed automated stuffing attacks to succeed.
## Recommendations
- **Authentication:** Enable phishing-resistant MFA for all VPN and administrative access.
- **Encryption:** Transition credential storage to the **PBKDF2** algorithm on Fortinet devices.
- **Monitoring:** Regularly review firewall logs for the creation of new accounts and unauthorized protocol sniffing.
- **Zero Trust:** Implement Geo-fencing and IP allow-listing for administrative access to management interfaces.