The FBI and U.S. Secret Service have issued a joint warning about an ongoing FortiBleed campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways around the world.
According to the advisory, more than 86,644 devices across 194 countries have been affected. Organizations that expose Fortinet management interfaces or remote-access services to the internet face a particularly high risk.
FortiBleed is not being described as one newly discovered Fortinet vulnerability. Instead, attackers are reportedly gaining access by using stolen, leaked, reused, or weak credentials.
The campaign also takes advantage of older SHA-256 password storage, allowing attackers to process stolen password data using distributed password-cracking systems.
Investigators discovered the scale of the operation after the attackers accidentally exposed a backend server containing their tools, target information, and operational workflows.
How the FortiBleed Campaign Works
The exposed infrastructure revealed what appears to be an organized initial-access operation.
Attackers reportedly scan the internet for FortiGate SSL VPN portals and then test credentials collected from previous breaches and infostealer logs.
They use techniques such as:
- Credential stuffing
- Password spraying
- Password cracking
- Testing stolen credentials
- Scanning exposed FortiGate systems
Once valid credentials are found, the access can potentially be sold to other cybercriminals.
Attackers may also create new administrator accounts after entering a FortiGate device. These accounts can help them maintain access even if the original compromised credentials are changed.
From there, threat actors can investigate Active Directory, identify privileged users, and attempt to move deeper into the victim’s network.
Attackers Can Lock Out Administrators
One of the most serious parts of the campaign is the possibility of defenders being locked out of their own Fortinet devices.
According to the advisory, attackers have reportedly changed passwords, disabled legitimate accounts, or removed existing administrator accounts after creating their own accounts.
This can make incident response much more difficult because security teams may lose control of the firewall or VPN gateway while the attackers continue operating.
The activity has also been linked to initial-access brokers that provide compromised access to ransomware groups. Reported ransomware connections include INC/Lynx and Payload, raising the possibility that a compromised FortiGate device could be the starting point for a much larger attack.
FortiBleed MITRE ATT&CK Techniques
The campaign has been associated with several MITRE ATT&CK techniques:
| Tactic | Technique | MITRE ID |
|---|---|---|
| Reconnaissance | Active Scanning | T1595 |
| Initial Access | Exploit Public-Facing Application | T1190 |
| Credential Access | Password Spraying | T1110.003 |
| Credential Access | Credential Stuffing | T1110.004 |
| Credential Access | Credential Dumping | T1003 |
| Credential Access | Password Cracking | T1110.002 |
| Persistence | Create Local Account | T1136.001 |
| Defense Evasion / Initial Access | Valid Accounts | T1078 |
| Discovery | Account Discovery | T1087 |
| Exfiltration | Exfiltration Over C2 Channel | T1041 |
| Impact | Account Access Removal | T1531 |
The combination of valid credentials, newly created accounts, and administrator lockouts can make the attack difficult to detect and contain.
What Organizations Should Do
Organizations using FortiGate devices should immediately review their administrative and VPN accounts and look for accounts they do not recognize.
The advisory specifically recommends checking for suspicious accounts such as:
forticloud-syncfgtsecureforti_support2Technical_support
Security teams should also investigate:
- Unexpected REST API keys
- Unusual configuration changes
- Suspicious authentication activity
- Connections to known malicious infrastructure
- Unexpected administrator accounts
- Successful suspicious logins
- Signs of lateral movement
- Attempts to modify firewall configurations
External management access should be restricted wherever possible. Organizations should use trusted hosts or local-in policies and avoid exposing administrative interfaces directly to the internet.
Administrators should also:
- Terminate active administrative and VPN sessions
- Reset Fortinet administrator and VPN passwords
- Enable phishing-resistant MFA for remote access and management
- Review firewall, VPN, authentication, and domain-controller logs
- Check whether administrator credentials use PBKDF2 instead of older password-hashing methods
The FortiBleed campaign shows why internet-facing firewalls and VPN gateways need the same level of monitoring and protection as other critical enterprise systems. A compromised edge device can provide attackers with a direct path into the wider network — and in some cases, even allow them to take control away from legitimate administrators.